Methods, systems, and computer readable media for automatic category 1 message filtering rules configuration by learning topology information from network function (NF) repository function (NRF)

US12556512B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12556512-B2
Application numberUS-202217902531-A
CountryUS
Kind codeB2
Filing dateSep 2, 2022
Priority dateSep 2, 2022
Publication dateFeb 17, 2026
Grant dateFeb 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for automatic configuration and use of Category 1 message filtering rules includes, at a network function (NF), subscribing, with an NF repository function (NRF), to receive notification of NF profile changes. The method further includes receiving, from the NRF and as a result of the subscribing, notification of an NF profile change. The method further includes automatically configuring, based on the notification of the NF profile change, at least one Category 1 message filtering rule implemented. The method further includes using the at least one Category 1 message filtering rule to filter service based interface (SBI) messages.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for automatic configuration and use of Category 1 message filtering rules, the method comprising: at a security edge protection proxy (SEPP) or a service communication proxy (SCP): subscribing, with an NF repository function (NRF), to receive notification of NF profile changes; receiving, from the NRF and as a result of the subscribing, notification of an NF profile change; automatically configuring, based on the notification of the NF profile change, at least one Category 1 message filtering rule, wherein the NF profile includes an authorization attribute and wherein automatically configuring the at least one Category 1 message filtering rule includes adding or updating a Category 1 message filtering rule to allow service based interface (SBI) messages containing hypertext transfer protocol (HTTP) methods corresponding to allowed scopes for an entity defined in the authorization attribute; and using, at the NF, the at least one Category 1 message filtering rule to filter the SBI messages, wherein using the at least one Category 1 message filtering rule to filter SBI messages includes receiving, from the entity, an SBI message containing an HTTP method that does not correspond to one of the allowed scopes for the entity, and, in response to determining that the HTTP method in the SBI message does not correspond to one of the allowed scopes for the entity, blocking the SBI message. 2 . The method of claim 1 wherein the SEPP or SCP comprises the SEPP. 3 . The method of claim 1 wherein the SEPP or SCP comprises the SCP. 4 . The method of claim 1 wherein subscribing with the NRF includes transmitting an nfStatusSubscribe message to the NRF. 5 . The method of claim 1 wherein receiving notification of the NF profile change includes receiving an nfStatusNotify message containing an NF profile. 6 . The method of claim 1 wherein receiving notification of the NF profile change includes receiving the notification in response to an NFRegister, NFUpdate, or NFDeregister service operation. 7 . The method of claim 1 wherein the scopes define allowed operations for the entity. 8 . The method of claim 1 wherein automatically configuring the at least one Category 1 message filtering rule includes automatically adding a Category 1 message filtering rule to a Category 1 message filtering rules database maintained by the NF. 9 . The method of claim 1 wherein using the Category 1 message filtering rule to filter SBI messages includes allowing or blocking messages arriving in a public land mobile network (PLMN) based on hypertext transfer protocol (HTTP) method type and resource uniform resource identifier (URI) parameters in the messages. 10 . A system for automatic configuration and use of Category 1 message filtering rules, the system comprising: a security edge protection proxy (SEPP) or a service communication proxy (SCP) including at least one processor and a memory; a Category 1 message filtering rules database stored in the memory; and a Category 1 message filtering rules manager executable by the at least one processor for subscribing, with an NF repository function (NRF), to receive notification of NF profile changes, receiving, from the NRF and as a result of the subscribing, notification of an NF profile change, automatically configuring, based on the notification of the NF profile change, at least one Category 1 message filtering rule in the Category 1 message filtering rules database; and using the at least one Category 1 message filtering rule to filter service based interface (SBI) messages, wherein the NF profile includes an authorization attribute, wherein automatically configuring the at least one Category 1 message filtering rule includes adding or updating a Category 1 message filtering rule to allow SBI messages containing hypertext transfer protocol (HTTP) methods corresponding to allowed scopes for an entity defined in the authorization attribute, and wherein using the at least one Category 1 message filtering rule to filter SBI messages includes receiving, from the entity, an SBI message containing an HTTP method that does not correspond to one of the allowed scopes for the entity, and, in response to determining that the HTTP method in the SBI message does not correspond to one of the allowed scopes for the entity, blocking the SBI message. 11 . The system of claim 10 wherein the SEPP or SCP comprises the SEPP. 12 . The system of claim 10 wherein SEPP or SCP comprises the SCP. 13 . The system of claim 10 wherein the Category 1 message filtering rules manager is configured to subscribe with the NRF by transmitting an nfStatusSubscribe message to the NRF. 14 . The system of claim 10 wherein the Category 1 message filtering rules manager is configured to receive the notification of the NF profile change in an nfStatusNotify message containing an NF profile. 15 . The system of claim 11 the Category 1 message filtering rules manager is configured to receive the notification of the NF profile change in response to an NFRegister, NFUpdate, or NFDeregister service operation. 16 . The system of claim 1 wherein the scopes define allowed operations for the entity. 17 . The system of claim 10 wherein the Category 1 message filtering rules manager is configured to allow or block messages arriving in a public land mobile network (PLMN) based on hypertext transfer protocol (HTTP) method type and resource uniform resource identifier (URI) parameters in the messages. 18 . A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: at a security edge protection proxy (SEPP) or a service communication proxy (SCP): subscribing, with an NF repository function (NRF), to receive notification of NF profile changes; receiving, from the NRF and as a result of the subscribing, notification of an NF profile change; automatically configuring, based on the notification of the NF profile change, at least one Category 1 message filtering rule, wherein the NF profile includes an authorization attribute and wherein automatically configuring the at least one Category 1 message filtering rule includes adding or updating a Category 1 message filtering rule to allow service based interface (SBI) messages containing hypertext transfer protocol (HTTP) methods corresponding to allowed scopes for an entity defined in the authorization attribute; and using, at the NF, the at least one Category 1 message filtering rule to filter the SBI messages, wherein using the at least one Category 1 message filtering rule to filter SBI messages includes receiving, from the entity, an SBI message containing an HTTP method that does not correspond to one of the allowed scopes for the entity, and, in response to determining that the HTTP method in the SBI message does not correspond to one of the allowed scopes for the entity, blocking the SBI message.

Assignees

Inventors

Classifications

  • Proxies · CPC title

  • using filters or firewalls · CPC title

  • Rule management · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12556512B2 cover?
A method for automatic configuration and use of Category 1 message filtering rules includes, at a network function (NF), subscribing, with an NF repository function (NRF), to receive notification of NF profile changes. The method further includes receiving, from the NRF and as a result of the subscribing, notification of an NF profile change. The method further includes automatically configurin…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0263. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).