Security policy deployment method and apparatus

US11489873B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11489873-B2
Application numberUS-201916359753-A
CountryUS
Kind codeB2
Filing dateMar 20, 2019
Priority dateSep 20, 2016
Publication dateNov 1, 2022
Grant dateNov 1, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A security policy deployment method and apparatus are provided, and the method includes: when a lifecycle state of a virtualized network function VNF changes, generating, by a management network element, a security policy of the VNF, where the security policy of the VNF is used to perform access control on the VNF; and sending, by the management network element, the security policy of the VNF to a control device. The management network element is a network element configured to perform lifecycle management on the VNF. By using the method or apparatus provided in embodiments of this application, the security policy of the VNF can be adjusted in time when the lifecycle state of the VNF changes, thereby greatly reducing a possibility that a bug occurs in the security policy of the VNF because the VNF changes.

First claim

Opening claim text (preview).

What is claimed is: 1. A security policy deployment method comprising: monitoring, by a management network element (MME), a lifecycle state of a virtualized network function (VNF), including obtaining configuration information of the VNF indicating a change of the lifecycle state of the VNF after the VNF is instantiated or created and before the VNF is terminated; in response to the change of the lifecycle state of the VNF comprising a change of one or more components of the VNF; generating, by the MME, a first security policy of the VNF, wherein the first security policy comprises a first network isolation policy and a first access control policy, wherein the first network isolation policy indicates network isolation between components in the VNF, and wherein the first access control policy is used to perform access control on an access request whose access target is a component in the VNF; sending, by the MME, the first security policy to the VNF; in response to the change of the lifecycle state of the VNF comprising a change of an object served by the VNF; generating, by the MME, a second security policy of the VNF, wherein the second security policy comprises a second network isolation policy and a second access control policy, wherein the second network isolation policy indicates network isolation between the VNF and other VNFs, and wherein the second access control policy is used to perform access control on an access request whose access target is the VNF; and sending, by the MME, the second security policy to a gateway device. 2. The method according to claim 1 , wherein sending, by the MME, the first security policy to the VNF comprises: sending, by the MME, the first security policy to the VNF by using a virtualized infrastructure manager (VIM) or an element management system (EMS). 3. The method according to claim 1 , wherein sending, by the MME, the second security policy to the gateway device comprises: sending, by the MME, the second security policy to the gateway device by using a virtualized infrastructure manager (VIM) or an element management system (EMS). 4. A security policy deployment apparatus comprising a transmitter, and a processor which is configured to: monitor, a lifecycle state of a virtualized network function (VNF), including obtaining configuration information of the VNF indicating a change of the lifecycle state of the VNF after the VNF is instantiated or created and before the VNF is terminated; in response to the change of the lifecycle state of the VNF comprising a change of component of the VNF; generate a first security policy of the VNF, wherein the first security policy comprises a first network isolation policy and a first access control policy, wherein the first network isolation policy indicates network isolation between components in the VNF, and wherein the first access control policy is used to perform access control on an access request whose access target is a component in the VNF; send the first security policy to the VNF; in response to the change of the lifecycle state of the VNF comprising a change of an object served by the VNF; generate a second security policy of the VNF, wherein the second security policy comprises a second network isolation policy and a second access control policy, wherein the second network isolation policy indicates network isolation between the VNF and other VNFs, and wherein the second access control policy is used to perform access control on an access request whose access target is the VNF; and send the second security policy to a gateway device. 5. The apparatus according to claim 4 , wherein the transmitter is further configured to cooperate with the processor to send the first security policy to the VNF by using a virtualized infrastructure manager (VIM) or an element management system (EMS). 6. The apparatus according to claim 4 , wherein the transmitter is further configured to: cooperate with the processor to send, by using a virtualized infrastructure manager (VIM) or an element management system (EMS), the second security policy to the gateway device, which is configured to provide the VNF with a network service. 7. A non-transitory, computer-readable medium having processor-executable instructions stored thereon, which when executed by a processor of a management network element (MME), cause the processor to implement a security policy deployment method including the following operations: monitoring a lifecycle state of a virtualized network function (VNF), including obtaining configuration information of the VNF indicating a change of the lifecycle state of the VNF after the VNF is instantiated or created and before the VNF is terminated; in response to the change of the lifecycle state of the VNF comprising a change of component of the VNF; generating a first security policy of the VNF, wherein the first security policy comprises a first network isolation policy and a first access control policy, wherein the first network isolation policy indicates network isolation between components in the VNF, and wherein the first access control policy is used to perform access control on an access request whose access target is a component in the VNF; sending the first security policy to the VNF; in response to the change of the lifecycle state of the VNF comprising a change of an object served by the VNF; generating a second security policy of the VNF, wherein the second security policy comprises a second network isolation policy and a second access control policy, wherein the second network isolation policy indicates network isolation between the VNF and other VNFs, and wherein the second access control policy is used to perform access control on an access request whose access target is the VNF; and sending, the second security policy to a gateway device. 8. The non-transitory, computer-readable medium according to claim 7 , wherein sending the first security policy to the VNF comprises: sending the first security policy to the VNF by using a virtualized infrastructure manager (VIM) or an element management system (EMS). 9. The non-transitory, computer-readable medium according to claim 7 , wherein sending the second security policy to the gateway device comprises: sending the second security policy to the gateway device by using a virtualized infrastructure manager (VIM) or an element management system (EMS).

Assignees

Inventors

Classifications

  • Provisioning of proxy services (store-and-forward switching systems in data switching networks H04L12/54) · CPC title

  • Network arrangements, protocols or services for supporting real-time applications in data packet communication (real-time or near real-time messaging, e.g. instant messaging [IM] H04L51/04; selective video distribution H04N21/00) · CPC title

  • Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements · CPC title

  • for initial configuration or provisioning, e.g. plug-and-play · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11489873B2 cover?
A security policy deployment method and apparatus are provided, and the method includes: when a lifecycle state of a virtualized network function VNF changes, generating, by a management network element, a security policy of the VNF, where the security policy of the VNF is used to perform access control on the VNF; and sending, by the management network element, the security policy of the VNF t…
Who is the assignee on this patent?
Huawei Tech Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 01 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).