METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR MITIGATING DENIAL OF SERVICE (DoS) ATTACKS AT NETWORK FUNCTIONS (NFs)
US-2022247779-A1 · Aug 4, 2022 · US
US12010550B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12010550-B2 |
| Application number | US-202117491128-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 30, 2021 |
| Priority date | Sep 30, 2021 |
| Publication date | Jun 11, 2024 |
| Grant date | Jun 11, 2024 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Disclosed are various embodiments for customer-defined capacity limit plans in communication networks. In one embodiment, a request for a service from a radio-based network is received from a first client device. A network function in the radio-based network is determined to be at a capacity limit. Service from the network function to a second client device to the network function is suspended in response to determining that the network function in the radio-based network is at the capacity limit and based at least in part on a rule set specific to the radio-based network. The first client device is provided access to the network function instead of the second client device.
Opening claim text (preview).
Therefore, the following is claimed: 1. A system, comprising: a radio-based network operated by a cloud provider network on behalf of a customer, the radio-based network comprised of a plurality of network functions; and at least one computing device in the cloud provider network configured to at least: providing a service from a network function set of the plurality of network functions to a first client device and denying the service to a second client device in response to at least one network function in the network function set being at a client device capacity limit according to at least one rule defined by the customer that establishes a priority of the first client device over the second client device, the client device capacity limit being an absolute capacity limit for the service beyond which the service cannot be provided to additional client devices; and configure the network function set in the radio-based network to implement the at least one rule defined by the customer instead of a default rule for handling the absolute capacity limit. 2. The system of claim 1 , wherein the default rule comprises at least one of: a round robin algorithm or a first-in-first-out algorithm. 3. The system of claim 1 , wherein a first priority level is associated with the first client device, a second priority level is associated with the second client device, and the first priority level is higher than the second priority level. 4. The system of claim 3 , wherein the first priority level applies to a first class of client devices, and the second priority level applies to a second class of client devices. 5. The system of claim 1 , wherein configuring the network function set to implement the at least one rule instead of the default rule for handling the client device capacity limit causes the network function set to provide network service to the first client device and suspend the network service to the second client device under the at least one rule rather than to deny the network service to the first client device under the default rule. 6. The system of claim 1 , wherein configuring the network function set to implement the at least one rule instead of the default rule for handling the absolute capacity limit causes the network function set to dynamically assign a network slice having a quality-of-service requirement to the first client device. 7. The system of claim 1 , wherein the radio-based network comprises a radio access network, the network function is implemented in the radio access network, and the absolute capacity limit corresponds to a maximum number of client devices concurrently served by the service. 8. The system of claim 1 , wherein network traffic from the first client device is associated with a higher quality-of-service parameter than network traffic from the second client device. 9. A computer-implemented method, comprising: operating a radio-based network by a cloud provider network on behalf of a customer, the radio-based network comprised of a plurality of network functions; providing a service from a network function set of the plurality of network functions to a first client device and denying the service to a second client device in response to at least one network function in the network function set being at a client device capacity limit according to at least one rule defined by the customer that establishes a priority of the first client device over the second client device, the client device capacity limit being an absolute capacity limit for the service beyond which the service cannot be provided to additional client devices; and configuring the network function set in the radio-based network to implement the at least one rule defined by the customer instead of a default rule for handling the absolute capacity limit. 10. The computer-implemented method of claim 9 , wherein the default rule comprises at least one of: a round robin algorithm or a first-in-first-out algorithm. 11. The computer-implemented method of claim 9 , wherein a first priority level is associated with the first client device, a second priority level is associated with the second client device, and the first priority level is higher than the second priority level. 12. The computer-implemented method of claim 11 , wherein the first priority level applies to a first class of client devices, and the second priority level applies to a second class of client devices. 13. The computer-implemented method of claim 9 , wherein configuring the network function set to implement the at least one rule instead of the default rule for handling the client device capacity limit causes the network function set to provide network service to the first client device and suspend the network service to the second client device under the at least one rule rather than to deny the network service to the first client device under the default rule. 14. The computer-implemented method of claim 9 , wherein configuring the network function set to implement the at least one rule instead of the default rule for handling the absolute capacity limit causes the network function set to dynamically assign a network slice having a quality-of-service requirement to the first client device. 15. A non-transitory computer-readable medium storing instructions executable in at least one computing device, wherein when executed the instructions cause the at least one computing device to at least: provide a service from a network function set of a plurality of network functions in a radio-based network to a first client device and denying the service to a second client device in response to at least one network function in the network function set being at a client device capacity limit according to at least one rule defined by a customer that establishes a priority of the first client device over the second client device, the client device capacity limit being an absolute capacity limit for the service beyond which the service cannot be provided to additional client devices, the radio-based network being operated by a cloud provider network on behalf of the customer; and configure the network function set in the radio-based network to implement the at least one rule defined by the customer instead of a default rule for handling the absolute capacity limit. 16. The non-transitory computer-readable medium of claim 15 , wherein the default rule comprises at least one of: a round robin algorithm or a first-in-first-out algorithm. 17. The non-transitory computer-readable medium of claim 15 , wherein a first priority level is associated with the first client device, a second priority level is associated with the second client device, and the first priority level is higher than the second priority level. 18. The non-transitory computer-readable medium of claim 17 , wherein the first priority level applies to a first class of client devices, and the second priority level applies to a second class of client devices. 19. The non-transitory computer-readable medium of claim 15 , wherein configuring the network function set to implement the at least one rule instead of the default rule for handling the client device capacity limit causes the network function set to provide network service to the first client device and suspend the network service to the second client device under the at least one rule rather than to deny the network service to the first client device under the default rule. 20. The non-transitory computer-readable medium of claim 15 , wherein configuring the netw
using specific QoS parameters for wireless networks, e.g. QoS class identifier [QCI] or guaranteed bit rate [GBR] (negotiating SLA or negotiating QoS H04W28/24) · CPC title
among network function virtualisation [NFV] entities; among edge computing entities, e.g. multi-access edge computing · CPC title
based on traffic conditions · CPC title
using dynamic resource allocation, e.g. in-call renegotiation requested by the user or requested by the network in response to changing network conditions · CPC title
QOS or priority aware · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.