Methods, systems, and computer readable media for automatically updating firewall rules to filter service-based interface (SBI) messages relating to new or updated services

US12363075B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12363075-B2
Application numberUS-202318236921-A
CountryUS
Kind codeB2
Filing dateAug 22, 2023
Priority dateAug 22, 2023
Publication dateJul 15, 2025
Grant dateJul 15, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for automatically generating and distributing firewall rules to filter service-based interface (SBI) messages relating to new or updated services includes maintaining a repository of firewall rules for updating a ruleset used by a core network firewall to filter SBI messages transmitted in a core network. The method further includes automatically retrieving, from an online archive of Third Generation Partnership Project (3GPP) standards documents, definitions of service operations performed on SBI interfaces in the core network. The method further includes automatically generating firewall rules based on the definitions of the service operations. The method further includes storing the firewall rules in the repository of firewall rules. The method further includes automatically distributing the firewall rules in the repository of firewall rules to the core network firewall.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for automatically generating and distributing firewall rules to filter service-based interface (SBI) message relating to new or updated services, the method comprising: maintaining a repository of firewall rules for updating a ruleset used by a core network firewall to filter service-based interface (SBI) messages transmitted in a core network; automatically retrieving, from an online archive of Third Generation Partnership Project (3GPP) standards documents, definitions of service operations performed on SBI interfaces in the core network; automatically generating firewall rules based on the definitions of the service operations; storing the firewall rules in the repository of firewall rules; and automatically distributing the firewall rules in the repository of firewall rules to the core network firewall. 2. The method of claim 1 wherein maintaining the repository of firewall rules includes maintaining the repository on a stand-alone network node dedicated to updating firewall rulesets. 3. The method of claim 1 wherein maintaining the repository of firewall rules includes maintaining the repository on a network node comprising an element management system (EMS) used to configure 5G network functions. 4. The method of claim 1 wherein automatically generating the firewall rules includes reading the definitions of the service operations in YAML files published in the archive and extracting firewall rule criteria from the YAML files. 5. The method of claim 4 wherein extracting the firewall rule criteria from the YAML files includes extracting SBI message attributes from the YAML files and using the SBI message attributes as the firewall rule criteria. 6. The method of claim 1 wherein automatically retrieving the definitions of the service operations includes periodically checking the archive for new or updated definitions of the service operations. 7. The method of claim 1 wherein automatically generating the firewall rules includes generating firewall rules to allow messages corresponding to new or updated service operations defined in the definitions of the service operations. 8. The method of claim 1 wherein the core network firewall comprises a security edge protection proxy (SEPP) and wherein automatically distributing the firewall rules includes automatically updating firewall rules used by the SEPP to filter ingress and egress inter-public land mobile network (PLMN) traffic. 9. The method of claim 8 comprising, at the SEPP, using the firewall rules to filter the ingress and egress inter-PLMN traffic. 10. The method of claim 1 wherein the core network firewall comprises a 5G core network firewall separate from a security edge protection proxy (SEPP) and wherein automatically distributing the firewall rules includes automatically updating the firewall rules used by the 5G core network firewall to filter the SBI messages. 11. A system for automatically generating and distributing firewall rules to filter service-based interface (SBI) message relating to new or updated services, the system comprising: a network node including at least one processor and a memory; a repository of firewall rules stored in the memory for updating a ruleset used by a core network firewall to filter service-based interface (SBI) messages transmitted in a core network; and an automated firewall rules generator/distributor implemented by the at least one processor for automatically retrieving, from an online archive of Third Generation Partnership Project (3GPP) standards documents, definitions of service operations performed on SBI interfaces in the core network, automatically generating firewall rules based on the definitions of the service operations, storing the firewall rules in the repository of firewall rules, and automatically distributing the firewall rules in the repository of firewall rules to the core network firewall. 12. The system of claim 11 wherein the network node comprises a stand-alone network node dedicated to updating firewall rules. 13. The system of claim 11 wherein the network node comprises an element management system (EMS) used to configure 5G network functions. 14. The system of claim 11 wherein, in generating the firewall rules, the automated firewall rules generator/distributor is configured to read the definitions of the service operations in YAML files published in the archive and extracting firewall rule criteria from the YAML files. 15. The system of claim 14 wherein, in extracting the firewall rule criteria from the YAML files, the automated firewall rules generator/distributor is configured to extract SBI message attributes from the YAML files and use the SBI message attributes as the firewall rule criteria. 16. The system of claim 11 wherein, in automatically retrieving the definitions of the service operations, the automated firewall rules generator/distributor is configured to periodically check the archive for new or updated definitions of the service operations. 17. The system of claim 11 wherein, in automatically generating the firewall rules, the automated firewall rules generator/distributor is configured to generate firewall rules to allow messages corresponding to new or updated service operations defined in the definitions of the service operations. 18. The system of claim 11 wherein the core network firewall comprises a security edge protection proxy (SEPP) and wherein, in automatically distributing the firewall rules, the automated firewall rules generator/distributor is configured to automatically update firewall rules used by the SEPP to filter ingress and egress inter-public land mobile network (PLMN) traffic. 19. The system of claim 11 wherein the core network firewall comprises a 5G core network firewall separate from a security edge protection proxy (SEPP) and, in automatically distributing the firewall rules, the automated firewall rules generator/distributor is configured to automatically update the firewall rules used by the 5G core network firewall to filter the SBI messages. 20. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: maintaining a repository of firewall rules for updating a ruleset used by a core network firewall to filter service-based interface (SBI) messages transmitted in a core network; automatically retrieving, from an online archive of Third Generation Partnership Project (3GPP) standards documents, definitions of service operations performed on SBI interfaces in the core network; automatically generating firewall rules based on the definitions of the service operations; storing the firewall rules in the repository of firewall rules; and automatically distributing the firewall rules in the repository of firewall rules to the core network firewall.

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12363075B2 cover?
A method for automatically generating and distributing firewall rules to filter service-based interface (SBI) messages relating to new or updated services includes maintaining a repository of firewall rules for updating a ruleset used by a core network firewall to filter SBI messages transmitted in a core network. The method further includes automatically retrieving, from an online archive of T…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0281. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 15 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).