SECURITY MANAGEMENT FOR NETWORK FUNCTION MESSAGING IN A COMMUNICATION SYSTEM

    公开(公告)号:US20210243165A1

    公开(公告)日:2021-08-05

    申请号:US17053127

    申请日:2019-05-10

    Abstract: In a communication system wherein a first security edge protection proxy (SEPP) element of a first network is operatively coupled to a second SEPP element of a second network, a method includes receiving, at the first SEPP element, a first message from a first network function in the first network addressed to a second network function in the second network, the first message comprising one of a request and a response line comprising a uniform resource identifier (URI) having a plurality of elements. The method also includes forming, at the first SEPP, a second message comprising encrypted and integrity protected portions, the encrypted portion comprising an encryption of at least a subset of the plurality of elements of the URI, the integrity protected portion comprising a structured representation of the URI wherein instances of elements in the subset are replaced with references to the encrypted portion.

    TRANSPORT METHOD SELECTION FOR DELIVERY OF SERVER NOTIFICATIONS

    公开(公告)号:US20200267201A1

    公开(公告)日:2020-08-20

    申请号:US16635527

    申请日:2017-08-04

    Abstract: Methods and apparatus, including computer program products, are provided for transport method selection of asynchronous notifications. In some example embodiments, there may be provided a method that includes sending, by a client, a hypertext transfer protocol request for at least one asynchronous notification to be sent by a server to the client, the hypertext transfer protocol request including at least one proposed transport method for carrying the at least one asynchronous notification; determining, by the client, whether a first transport method selected by the server from the at least one proposed transport method is successfully established; and when the determination is that the first transport method is not established successfully, sending, by the client, another hypertext transfer protocol request to the server, the other hypertext transfer protocol request including at least one other proposed transport method. Related systems, methods, and articles of manufacture are also described.

    METHODS AND APPARATUSES FOR MULTI-TIERED VIRTUALIZED NETWORK FUNCTION SCALING

    公开(公告)号:US20200012510A1

    公开(公告)日:2020-01-09

    申请号:US16494932

    申请日:2017-03-24

    Abstract: Systems, methods, apparatuses, and computer program products for multi-tiered virtualized network function (VNF) scaling are provided. One method includes detecting a need to scale at least one virtualized network function component (VNFC) implemented as a container, monitoring resource utilization by containers and determining remaining capacity within a current virtual machine hosting the containers, and deciding an allocation of the container to a virtual machine based at least on the resource utilization and the remaining capacity. When it is determined that the remaining capacity is low, the method may further include vertical scaling of the current virtual machine by allocating additional virtualized resources to the current virtual machine, and/or horizontal scaling of the current virtual machine by instantiating a new virtual machine and deploying the container to the newly instantiated virtual machine.

    METHOD AND APPARATUS FOR SECURE MESSAGING BETWEEN NETWORK FUNCTIONS

    公开(公告)号:US20220038433A1

    公开(公告)日:2022-02-03

    申请号:US17277210

    申请日:2019-09-10

    Abstract: In accordance with an example aspect, there is provided an apparatus, the apparatus being a security edge proxy configured to implement application layer security for data exchanged between two core networks, the apparatus being configured at least to: process a protocol message received in the apparatus to generate an inter-network message based on the received protocol message, the inter-network message comprising a first part and a second part, transmit the inter-network message toward a second security edge proxy, wherein the first part is integrity protected but not encrypted and comprises first content elements of the received protocol message, wherein the second part is integrity protected and encrypted and comprises second content elements of the received protocol message as well as corresponding path elements indicating locations in the protocol message where the second content elements are located within the protocol message.

Patent Agency Ranking