WO2012163405A1 - Communication control in communication networks - Google Patents

Communication control in communication networks Download PDF

Info

Publication number
WO2012163405A1
WO2012163405A1 PCT/EP2011/058928 EP2011058928W WO2012163405A1 WO 2012163405 A1 WO2012163405 A1 WO 2012163405A1 EP 2011058928 W EP2011058928 W EP 2011058928W WO 2012163405 A1 WO2012163405 A1 WO 2012163405A1
Authority
WO
WIPO (PCT)
Prior art keywords
communication control
control rule
firewall
network address
address translation
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2011/058928
Other languages
French (fr)
Inventor
Vesa Pauli Hellgren
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Solutions and Networks Oy
Original Assignee
Nokia Siemens Networks Oy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nokia Siemens Networks Oy filed Critical Nokia Siemens Networks Oy
Priority to PCT/EP2011/058928 priority Critical patent/WO2012163405A1/en
Publication of WO2012163405A1 publication Critical patent/WO2012163405A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0236Filtering by address, protocol, port number or service, e.g. IP-address or URL
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0263Rule management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/088Access security using filters or firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M15/00Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP
    • H04M15/66Policy and charging system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/16Central resource management; Negotiation of resources or communication parameters, e.g. negotiating bandwidth or QoS [Quality of Service]
    • H04W28/18Negotiating wireless communication parameters
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W72/00Local resource management

Definitions

  • the present invention relates to communication control in communication systems.
  • the present invention relates to a method, apparatuses, a system and a computer program product for controlling network address translator and firewall policies in a telecommunication network.
  • IPv4 Internet Protocol version 4
  • NAT network address translator
  • TCP/UDP transmission control protocol / user datagram protocol
  • a NAT44 device usually randomizes the port selection, and this practice helps enhance the security in the network. However, such practice increases the translation logging task on a NAT44 device.
  • Each NAT44 translation log entry corresponds to a unique IP flow and typically includes the destination address and port, translated source address (the shared IPv4
  • Firewalls are deployed in the third generation of mobile phone standards (3G) and beyond networks at various places for protection against attacks and for access control to de- fine which host is permitted to use certain services or ap ⁇ plications. Some examples of possible locations for firewalls are :
  • IMS IP Multimedia Subsystem
  • IP-5tuple The most common type of firewall is a packet filter that per ⁇ mits traffic flow identified by the so called IP-5tuple:
  • Such packet filters are implemented in a Gateway General Packet Radio Service (GPRS) Support Node (GGSN) of today's 2.5G and 3G networks, they are used for filtering based on traffic flow templates (TFT, see e.g. section 15.3. of 3GPP TS 23.060, version 10.3.0) or service-based local policy (SBLP, see e.g. section 4 of 3GPP TS 29.207, version 6.5.0).
  • GPRS General Packet Radio Service
  • GGSN Gateway General Packet Radio Service Support Node
  • TFT traffic flow templates
  • SBLP service-based local policy
  • PDF Policy Decision Function
  • PEF Policy Enforce ⁇ ment Function
  • PCC Policy and Charging Control
  • PCEF Poli ⁇ cy and Charging Enforcement Function
  • the general 3GPP IMS architecture is specified in 3GPP TS 23.228 (see e.g. version 11.0.0) .
  • Annex G defines the refer ⁇ ence architecture for the case where NAT and/or firewall is invoked between a user equipment (UE) and the IMS domain, as illustrated in Figure 1.
  • This architecture maps to the basic PCC architecture, where a Proxy Call Session Control function (P-CSCF) is an Application Function (AF) .
  • P-CSCF Proxy Call Session Control function
  • AF Application Function
  • NAT and firewall function may be co-located with PCEF in one gateway node, see Figure 2.
  • PCC rule procedures are specified in section 4 of 3GPP TS 29.212 (see e.g. version 11.0.1) and illustrated in Figure 3.
  • PCRF International Mobile Subscriber Identity
  • ISDN Mobile Station International Integrated Services Digital Net- work
  • PCRF returns PCC rule(s) in a Credit Control Answer (CCA) Diameter message.
  • PCEF then activates the PCC rule for the activated PDN connection.
  • NAT function requires maintaining state information about the active NAT bindings.
  • Stateful firewalls are similar to NAT in that sense that they also maintain state information about the active traffic flows, so that they are able to allow or block traffic if the flow is initiated from a wrong source direction or there are too many active flows.
  • firewall may allow uplink packet from a user equipment (UE) to pass to any Hypertext Transfer protocol (HTTP) server, but traffic from a HTTP server is not allowed if the UE has never sent any traffic to it (in this way the firewall can prevent e.g. billing attacks) .
  • HTTP Hypertext Transfer protocol
  • the term "binding" is used for the re ⁇ source usage related to single traffic flow, where NAT and/or firewall function is enabled.
  • 3GPP has not defined how the NAT/firewall policies are to be managed if the NAT/firewall function is implemented as part of GGSN or P-GW.
  • Gateway nodes do not have infinite resources, so there is a limit for active bindings.
  • the present invention aims to define NAT and firewall poli ⁇ cies in a policy control server and to enforce those policies in the gateway product (s) which implement NAT and/or firewall function.
  • the main focus is in the 3GPP architecture, where policy control is implemented in PCRF and policy enforcement is implemented in GGSN or P-GW nodes.
  • a method for controlling firewall or network address translation function comprising receiving at a policy and charging enforcement function a request to activate a first communication control rule, for example a policy and charging rule, the rule comprising at least one communication control rule parameter, wherein the communication control rule is as- sociated with controlling firewall or network address trans ⁇ lation function policy.
  • the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication control rule, or a binding priority level of the communication control rule.
  • the method further comprising es storing the first communication control rule.
  • the first communication control rule is stored as a part of local policy and charging rules at the policy and charging enforcement function.
  • the method further compris es receiving the first communication control rule from a pol icy and charging rules function.
  • the first communication control rule is received in an attribute value pair via Gx interface.
  • the first communication control rule is received in a diameter credit control answer message.
  • the first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the method further comprises checking whether at least the guaranteed number of firewall or network address translation function bindings are available.
  • the method further comprising es reserving resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation in case at least the guaranteed number of firewall or network address translation function bindings are available.
  • the method further compris- es checking whether the first communication control rule comprises a binding pre-emption capability parameter in case at least the guaranteed number of firewall or network address translation function bindings are not available.
  • the method further compris- es reporting communication control rule activation failure in case the first communication control rule does not comprise a binding pre-emption capability parameter.
  • the method further compris- es checking whether at least one second activated communica ⁇ tion control rule, for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication con ⁇ trol rule comprises a lower binding priority level than the first communication control rule in case the first communica ⁇ tion control rule comprises a binding pre-emption capability parameter .
  • at least one second activated communica ⁇ tion control rule for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication con ⁇ trol rule comprises a lower binding priority level than the first communication control rule in case the first communica ⁇ tion control rule comprises a binding pre-emption capability parameter .
  • one second activated communication con- trol rule comprises a binding pre-emption vulnerability para ⁇ meter and a lower binding priority level than the first com ⁇ munication control rule and the method further comprises pre ⁇ empting (S5) at least one firewall or network address trans ⁇ lation function binding associated with the one second acti- vated communication control rule, and reserving resources for the guaranteed number of firewall or network address transla ⁇ tion function bindings as part of the first communication control rule activation.
  • At least two second activated communica ⁇ tion control rules comprise a binding pre-emption vulnerabil ⁇ ity parameter and a lower binding priority level than the first communication control rule and the method further com ⁇ prises comparing binding priority levels of the at least two second activated communication control rules.
  • the method further compris ⁇ es pre-empting at least one firewall or network address translation function binding associated with a second activated communication control rule with lowest priority level, and reserving resources for the guaranteed number of firewall or network address translation function bindings for activating the first communication control rule.
  • the method further compris- es pre-empting firewall or network address translation function bindings associated with a second activated communica ⁇ tion control rule such that the guaranteed number of firewall or network address translation function bindings comprised in the first communication control rule are available.
  • the first communication control rule comprises a policy and charging rule.
  • the second communication control rule comprises a policy and charging rule.
  • the communication control parameter rule comprises a policy and charging rule parameter.
  • an apparatus comprising an input configured to receive a request to activate a first communication control rule, for example a policy and charging rule, the rule comprising at least one communication control rule parameter, wherein the communication control rule is associated with controlling firewall or network address translation function policy.
  • a first communication control rule for example a policy and charging rule
  • the rule comprising at least one communication control rule parameter, wherein the communication control rule is associated with controlling firewall or network address translation function policy.
  • the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication con- trol rule, or a binding priority level of the communication control rule.
  • the apparatus further compris- es a memory configured to store the first communication con ⁇ trol rule.
  • the memory is further confi ⁇ gured to store the first communication control rule as a part of local policy and charging rules.
  • the input is further confi ⁇ gured to receive the first communication control rule from a policy and charging rules function. In some embodiments, the input is further configured to receive the first communica ⁇ tion control rule in an attribute value pair via Gx inter- face. In some embodiments, the input is further configured to receive the first communication control rule in a diameter credit control answer message.
  • the first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the apparatus further comprises a processor configured to check whether at least the guaranteed number of firewall or network address translation function bindings are available.
  • the processor is further configured to reserve resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation in case at least the guaranteed number of firewall or network address translation function bindings are available.
  • the processor is further configured to check whether the first communication control rule comprises a binding pre-emption capability parameter in case at least the guaranteed number of firewall or network address translation function bindings are not available.
  • the apparatus further comprises an output configured to report communication control rule activation failure in case the first communication con- trol rule does not comprise a binding pre-emption capability parameter .
  • the processor is further configured to check whether at least one second activated commu- nication control rule, for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication control rule comprises a lower binding priority level than the first communication control rule in case the first commu- nication control rule comprises a binding pre-emption capa ⁇ bility parameter.
  • at least one second activated commu- nication control rule for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication control rule comprises a lower binding priority level than the first communication control rule in case the first commu- nication control rule comprises a binding pre-emption capa ⁇ bility parameter.
  • one second activated communication con ⁇ trol rule comprises a binding pre-emption vulnerability para- meter and a lower binding priority level than the first com ⁇ munication control rule
  • the processor is further configured to pre-empt at least one firewall or network address translation function binding associated with the one second activated communication control rule, and to reserve re- sources for the guaranteed number of firewall or network ad ⁇ dress translation function bindings as part of the first com ⁇ munication control rule activation.
  • At least two second activated communica- tion control rules comprise a binding pre-emption vulnerabil ⁇ ity parameter and a lower binding priority level than the first communication control rule and the processor is further configured to compare binding priority levels of the at least two second activated communication control rules.
  • the processor is further configured to pre-empt at least one firewall or network ad- dress translation function binding associated with a second activated communication control rule with lowest priority level, and to reserve resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation.
  • the processor is further configured to pre-empt firewall or network address translation function bindings associated with a second activated communication control rule such that the guaranteed number of firewall or network address translation function bindings comprised in the first communication control rule are available.
  • the apparatus comprises a policy and charging enforcement function.
  • the appa ratus is located in a gateway general packet radio service support node or in a packet data network gateway.
  • the first communication control rule comprises a policy and charging rule.
  • the second communication control rule comprises a policy and charging rule.
  • the communication control parameter rule comprises a policy and charging rule parameter.
  • an apparatus comprising an output configured to send a first communication control rule, for example a policy and charging rule, to a policy and charging enforcement function, the rule comprising at least one communication control rule parameter, wherein the communication control rule is associated with controlling firewall or network address transla ⁇ tion function policy.
  • the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication control rule, or a binding priority level of the communication control rule.
  • the apparatus comprises a policy and charging rules function.
  • the first communication control rule comprises a policy and charging rule.
  • the second communication control rule comprises a policy and charging rule.
  • the communication control parameter rule comprises a policy and charging rule parameter.
  • a computer program product comprising code means adapted to perform all the steps of any of claims 1 to 17 when the program is run on a processor.
  • Embodiments of the present invention may have one or more of following advantages: defining a new NAT/firewall policy architecture in 3GPP simple support for NAT/firewall policies
  • Figure 1 illustrates a reference architecture for a case where NAT and/or firewall is invoked between a user equipment (UE) and the IMS domain, according to 3GPP TS 23.228.
  • UE user equipment
  • Figure 2 illustrates a basic PCC reference architecture.
  • Figure 3 illustrates a basic PCC rule procedure according 3GPP TS 29.212.
  • Figures 4a, 4b and 4c illustrate a method according to an ex ⁇ emplary embodiment of the invention.
  • FIGS 5a and 5b illustrate an apparatus according to an ex emplary embodiment of the invention.
  • Figure 6 illustrates an apparatus according to an exemplary embodiment of the invention.
  • Figure 7 illustrates a signaling flow when a default bearer is activated in a P-GW according to an exemplary embodiment of the invention.
  • Figure 8 illustrates a signaling flow related to an IMS voice call according to an exemplary embodiment of the invention.
  • a file transfer us ⁇ ing a file-sharing application e.g. BitTorrent
  • the present invention defines policies depending on the ap ⁇ plications and not just on the subscribers or PDN connec ⁇ tions.
  • the defined policies may allow pre- empting the already allocated resources, so that when e.g. resources are allocated to a low priority best-effort appli ⁇ cation, a high priority application having guaranteed resource may pre-empt some of the resources already given to the best-effort application.
  • the invention is generic for all NAT variants, so the same invention can be applied for e.g. NAT44 and NAT64.
  • the firewall/policy architecture may comprise the following nodes: - PCRF 200, which defines the NAT/firewall policies for
  • 3GPP nodes in addition to other policy control.
  • PCEF 100 which implements the enforcement of
  • PCEF 100 is one of the functions of a user plane gateway 300, e.g. GGSN or P-GW.
  • Actual NAT/firewall rules may be defined as extensions to the existing PCC rules of the 3GPP PCC architecture. Particular ⁇ ly, the following new parameters may be added to the existing PCC rule (s) :
  • These new PCC rule parameters may be passed to the PCEF 100 from the PCRF 200 as a part of the new Gx interface applica ⁇ tion attribute-value-pairs (AVPs) when a PCC rule is in ⁇ stalled or modified by the PCRF 200, as in Figure 3.
  • AVPs attribute-value-pairs
  • These new PCC rule parameters may also be defined in local PCC rules, which are activated based on the rulebases installed by the PCRF 200.
  • PCRF 200 may also enable/disable NAT, and depending on this infor ⁇ mation, the binding policies in the PCC rule may be applied to NAT or firewall function in the PCEF 100.
  • these NAT/firewall rules may be defined as separate NAT/firewall rules, instead of as extensions to the existing PCC rules.
  • the invented method applies also in this case.
  • PCC rule and “PCC rule parameter” is used, but according to the invention they may as well be replaced with the terms “NAT/firewall rule” and “NAT/firewall rule parameter”.
  • the invention defines a new NAT/firewall policy architecture, where NAT/firewall policies are controlled by the PCRF 200, which handles all the Quality of Service (QoS) and charging policies in the 3GPP architecture.
  • QoS Quality of Service
  • the benefit of this ap ⁇ proach is that support for NAT/firewall policies may be done by adding a few new AVPs in the Gx interface. If local PCC rules are used, then only the PCC rule configuration in the PCEF 100 requires changes. Having common node for handling all policies allows having synergies when making the policy decisions.
  • MIDCOM Middlebox Communication working group
  • PCRF 200 may install NAT/firewall policies to the PCEF 100, which may then use the MIDCOM pro ⁇ tocol to define the actual NAT/firewall rules for the user plane function where NAT or firewall function is implemented.
  • Invention defines maximum and guaranteed number of bindings per PCC rule. This may allow more granular resource manage- ment than the prior art solutions, which allocated bindings per subscriber or per PDN connection. It may be possible to define that e.g. subscriber may have one guaranteed binding per for e-mail traffic, while the HTTP traffic may have maxi ⁇ mum 16 concurrent bindings active without any guaranteed num- ber of bindings.
  • the defined number of bindings may be reserved when the PCC rule is activated (see below) .
  • maximum number of bindings of the PCC rule defines whether a new binding can be reserved.
  • the PCEF 100 may receive (step SI) a request to activate a PCC rule, where the rule may comprise at least one PCC rule parameter.
  • the PCEF 100 may check whether the PCC rule requires guaranteed number of bindings, (step S2) . If guaranteed bindings are required, then PCEF 100 may reserve (step S3a) them when the PCC rule is activated. If there are not enough bindings available, PCEF 100 may check the binding pre-emption capability (BPC) value of the PCC rule (step S3b) . If BPC is not defined, then the PCC rule activation may fail.
  • BPC binding pre-emption capability
  • the PCEF 100 may check if there are any binding reservations done by other PCC rules where the binding pre-emption vulnerability (BPV) value indicates that its bindings can be pre-empted and if those PCC rules have lower priority (BPL) than the new PCC rule (step S4b) . If that is not the case, then the PCC rule activation may fail and the PCEF 100 may report PCC rule activation failure (step S4a) . Otherwise the binding (s) reserved by the other PCC rule may be released and allocated to the new PCC rule (step S5b) . If pre-emption is possible for multiple PCC rules, then BPL may be used to select the PCC rule with the lowest priority (steps S5a and S6a) .
  • BPL binding pre-emption vulnerability
  • Pre-empting the other PCC rule may re ⁇ lease enough resource allocations done as part of the activa ⁇ tion of the other PCC rule for the "first" PCC rule.
  • the other already activated PCC rule has 1000 bind ⁇ ings.
  • the PCEF 100 may report this to the PCRF 200 according to the section 4.5.12 of 3GPP TS 29.212 (e.g. version 11.0.1): If the installation/activation of one or more PCC rules fails using a PULL mode (i.e. the PCRF 200 installs/activates a rule using a CCA command) the PCEF 100 may send the PCRF 200 a new CCR command and include the Rule-Failure-Code AVP .
  • the same pre-emption method is applied also when a new bind ⁇ ing needs to be activated for the PCC rule, i.e. there are no free guaranteed level bindings available in the PCC rule, but the number of bindings does not exceed the maximum number of bindings of the PCC rule.
  • the main difference is that if the new binding cannot be reserved, then the PCC rule may remain active .
  • the PCEF 100 may com ⁇ prise an input 101 configured to receive a request to acti- vate a PCC rule.
  • the PCEF may further comprise a memory 102 configured to store the PCC rule, a processor 103 configured to check whether a guaranteed number of firewall or network address translation function bindings are available, and an output 104 configured to report PCC rule activation failure in case the PCC rule cannot be activated.
  • the PCEF 100 may be located in a user plane gateway 300, e.g. in a GGSN or in a PDN-GW.
  • the PCRF may comprise an output 201 configured to send a PCC rule to a PCEF 100.
  • the PCRF 200 may further comprise an input configured to receive a failure report from the PCEF 100.
  • the processor 103 may comprise a central processing unit
  • the input 101 may comprise a receiver or any other means for receiving.
  • the output 104, 201 may comprise a transceiver or any other means for transmitting.
  • the processor 103, the memory 102, the in- put 101, and the output 104 may exchange information over an internal interface of the PCEF 100.
  • the input 101 and the output 104 of the PCEF 100 may be func ⁇ tionalities running on the processor 103 of the PCEF 100 or may alternatively be separate functional entities or means.
  • the input 101 and the output 104, 201 may also be implemented as integral transceivers or may be implemented e.g. as physi ⁇ cal transmitters/receivers for transceiving via the air in ⁇ terface, as routing entities for sending/receiving data pack- ets in a PS (packet switched) network, or as any suitable combination thereof.
  • the processor 103 may be configured to process various data inputs and to control input 101 and the output 104.
  • the appa- ratus 100, 200 may further comprise a memory that may serve for storing code means for carrying out e.g. the methods ac ⁇ cording to the examples of the present invention, e.g. when run e.g. on the processor 103.
  • the PCC rule requested to be activated may be associated with controlling firewall or network address translation function policy and comprise at least one policy and charging rule parameter.
  • the parame ⁇ ter may be e.g.
  • a maximum number of firewall or network address translation function bindings for an application a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the policy and charging rule, a binding pre ⁇ emption vulnerability of the policy and charging rule, or a binding priority level of the policy and charging rule.
  • a serving gateway (S-GW) 400 may request a new de ⁇ fault bearer in the P-GW 300.
  • the P-GW 300 may then send an initial CCR message to the PCRF 200 in order to receive poli ⁇ cies, including the NAT/firewall policies.
  • the CCA message returned from the PCRF 200 may include PCC rules or PCC rule- bases which define the policies.
  • the P-GW 300 may then acti ⁇ vate the PCC rules for the default bearer and make binding reservations according to the NAT/firewall policies. Default bearer activation may be completed when the P-GW 300 returns create session response to the S-GW 400.
  • FIG 8 shows an example of a signaling flow related to an IMS voice call.
  • the IMS system which corresponds to an AF 500 in the PCC architecture, may send a request to a PCRF 200 indicating that an IMS voice call is required.
  • the PCRF 200 may send a Re-Auth-Request (RAR) message to a P-GW 300, con ⁇ taining a PCC rule which conventionally triggers dedicated bearer activation.
  • RAR Re-Auth-Request
  • the PCC rule may define firewall poli ⁇ cies for the voice call.
  • the P-GW 300 may create a new dedi- cated bearer for the voice call and it may also make the re ⁇ quired binding reservations.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

A method is provided for controlling firewall or network address translation function comprising receiving a request to activate a first communication control rule, said rule comprising at least one communication control rule parameter wherein said communication control rule is associated with controlling firewall or a network address translation function policy.

Description

Description
Title
Communication control in communication networks
FIELD OF THE INVENTION
The present invention relates to communication control in communication systems. In particular, the present invention relates to a method, apparatuses, a system and a computer program product for controlling network address translator and firewall policies in a telecommunication network.
BACKGROUND ART
There are currently several Internet Protocol (IP) version 4 (IPv4) address sharing mechanisms such as network address translator (NAT), e.g. NAT44, because of shortage of IPv4 addresses. When an IP flow is initiated from a user side and its source IPv4 address is replaced by a shared IPv4 address at a NAT44 device, the source transmission control protocol / user datagram protocol (TCP/UDP) port in the IPv4 packet is also replaced by one dynamically allocated by the NAT44 device, most likely from a single port pool, and as such, the IP flow can be uniquely identified end-to-end. A NAT44 device usually randomizes the port selection, and this practice helps enhance the security in the network. However, such practice increases the translation logging task on a NAT44 device. Each NAT44 translation log entry corresponds to a unique IP flow and typically includes the destination address and port, translated source address (the shared IPv4
address) , translated source port (the one allocated by the NAT44 device), original source address and port, etc. It requires large volume of storage and also processing capacity on a NAT44 device for such operation. Firewalls are deployed in the third generation of mobile phone standards (3G) and beyond networks at various places for protection against attacks and for access control to de- fine which host is permitted to use certain services or ap¬ plications. Some examples of possible locations for firewalls are :
at the changeover point between radio access networks and an IP-based packet core
inside the packet core network to make attacks more dif¬ ficult (detection of distributed attacks)
at administrative borders between two operators
at the entry point of an IP Multimedia Subsystem (IMS) and
towards the public internet
The most common type of firewall is a packet filter that per¬ mits traffic flow identified by the so called IP-5tuple:
source address and port number, destination address and port number, and the higher-layer protocol (usually TCP or UDP) . Such packet filters are implemented in a Gateway General Packet Radio Service (GPRS) Support Node (GGSN) of today's 2.5G and 3G networks, they are used for filtering based on traffic flow templates (TFT, see e.g. section 15.3. of 3GPP TS 23.060, version 10.3.0) or service-based local policy (SBLP, see e.g. section 4 of 3GPP TS 29.207, version 6.5.0).
For policy control in IMS, a Policy Decision Function (PDF) entity has been specified; the corresponding Policy Enforce¬ ment Function (PEF) is located in the GGSN. Lately, this PEF has been changed to a Policy and Charging Control (PCC) ar¬ chitecture which will unify the previously separate systems for policy and charging control. In this new architecture, the tasks of a PDF are carried out by a Policy and Charging
Rules Function (PRCF) , whereas the PEF is included in a Poli¬ cy and Charging Enforcement Function (PCEF) , which is still located inside the GGSN or a packet data network (PDN) gate¬ way (P-GW) .
The general 3GPP IMS architecture is specified in 3GPP TS 23.228 (see e.g. version 11.0.0) . Annex G defines the refer¬ ence architecture for the case where NAT and/or firewall is invoked between a user equipment (UE) and the IMS domain, as illustrated in Figure 1. This architecture maps to the basic PCC architecture, where a Proxy Call Session Control function (P-CSCF) is an Application Function (AF) . NAT and firewall function may be co-located with PCEF in one gateway node, see Figure 2.
The basic PCC rule procedures are specified in section 4 of 3GPP TS 29.212 (see e.g. version 11.0.1) and illustrated in Figure 3. When a PDN connection is activated in a PCEF, the PCEF sends information about the PDN connection to PCRF (including e.g. International Mobile Subscriber Identity (IMSI), Mobile Station International Integrated Services Digital Net- work (ISDN) Number (MSISDN) , etc.) in a Credit Control Request (CCR) Diameter message and the PCRF returns PCC rule(s) in a Credit Control Answer (CCA) Diameter message. PCEF then activates the PCC rule for the activated PDN connection.
NAT function requires maintaining state information about the active NAT bindings. Stateful firewalls are similar to NAT in that sense that they also maintain state information about the active traffic flows, so that they are able to allow or block traffic if the flow is initiated from a wrong source direction or there are too many active flows. For example, firewall may allow uplink packet from a user equipment (UE) to pass to any Hypertext Transfer protocol (HTTP) server, but traffic from a HTTP server is not allowed if the UE has never sent any traffic to it (in this way the firewall can prevent e.g. billing attacks) . The term "binding" is used for the re¬ source usage related to single traffic flow, where NAT and/or firewall function is enabled. 3GPP has not defined how the NAT/firewall policies are to be managed if the NAT/firewall function is implemented as part of GGSN or P-GW. In particular, there are no methods for de¬ fining how to control the resource usage related to active bindings. Gateway nodes do not have infinite resources, so there is a limit for active bindings.
SUMMARY
It is therefore an object of this invention to address some of the above mentioned problems by providing a method, appa¬ ratuses, a system and a computer program product for communication control, e.g. controlling NAT and firewall policies, in mobile telecommunication systems.
The present invention aims to define NAT and firewall poli¬ cies in a policy control server and to enforce those policies in the gateway product (s) which implement NAT and/or firewall function. The main focus is in the 3GPP architecture, where policy control is implemented in PCRF and policy enforcement is implemented in GGSN or P-GW nodes.
According to a first aspect of the invention, there is pro¬ vided a method for controlling firewall or network address translation function comprising receiving at a policy and charging enforcement function a request to activate a first communication control rule, for example a policy and charging rule, the rule comprising at least one communication control rule parameter, wherein the communication control rule is as- sociated with controlling firewall or network address trans¬ lation function policy.
According to some embodiments, the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication control rule, or a binding priority level of the communication control rule.
According to further embodiments, the method further compris es storing the first communication control rule. In some em¬ bodiments, the first communication control rule is stored as a part of local policy and charging rules at the policy and charging enforcement function.
According to further embodiments, the method further compris es receiving the first communication control rule from a pol icy and charging rules function. In some embodiments, the first communication control rule is received in an attribute value pair via Gx interface. In some embodiments, the first communication control rule is received in a diameter credit control answer message.
According to further embodiments, the first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the method further comprises checking whether at least the guaranteed number of firewall or network address translation function bindings are available.
According to further embodiments, the method further compris es reserving resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation in case at least the guaranteed number of firewall or network address translation function bindings are available.
According to further embodiments, the method further compris- es checking whether the first communication control rule comprises a binding pre-emption capability parameter in case at least the guaranteed number of firewall or network address translation function bindings are not available.
According to further embodiments, the method further compris- es reporting communication control rule activation failure in case the first communication control rule does not comprise a binding pre-emption capability parameter.
According to further embodiments, the method further compris- es checking whether at least one second activated communica¬ tion control rule, for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication con¬ trol rule comprises a lower binding priority level than the first communication control rule in case the first communica¬ tion control rule comprises a binding pre-emption capability parameter .
In some embodiments, one second activated communication con- trol rule comprises a binding pre-emption vulnerability para¬ meter and a lower binding priority level than the first com¬ munication control rule and the method further comprises pre¬ empting (S5) at least one firewall or network address trans¬ lation function binding associated with the one second acti- vated communication control rule, and reserving resources for the guaranteed number of firewall or network address transla¬ tion function bindings as part of the first communication control rule activation.
In some embodiments, at least two second activated communica¬ tion control rules comprise a binding pre-emption vulnerabil¬ ity parameter and a lower binding priority level than the first communication control rule and the method further com¬ prises comparing binding priority levels of the at least two second activated communication control rules. According to further embodiments, the method further compris¬ es pre-empting at least one firewall or network address translation function binding associated with a second activated communication control rule with lowest priority level, and reserving resources for the guaranteed number of firewall or network address translation function bindings for activating the first communication control rule.
According to further embodiments, the method further compris- es pre-empting firewall or network address translation function bindings associated with a second activated communica¬ tion control rule such that the guaranteed number of firewall or network address translation function bindings comprised in the first communication control rule are available.
According to some embodiments the first communication control rule comprises a policy and charging rule. According to some embodiments the second communication control rule comprises a policy and charging rule. According to some embodiments the communication control parameter rule comprises a policy and charging rule parameter.
According to a second aspect of the invention, there is pro¬ vided an apparatus comprising an input configured to receive a request to activate a first communication control rule, for example a policy and charging rule, the rule comprising at least one communication control rule parameter, wherein the communication control rule is associated with controlling firewall or network address translation function policy.
According to some embodiments, the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication con- trol rule, or a binding priority level of the communication control rule.
According to some embodiments, the apparatus further compris- es a memory configured to store the first communication con¬ trol rule. In some embodiments, the memory is further confi¬ gured to store the first communication control rule as a part of local policy and charging rules.
According to some embodiments, the input is further confi¬ gured to receive the first communication control rule from a policy and charging rules function. In some embodiments, the input is further configured to receive the first communica¬ tion control rule in an attribute value pair via Gx inter- face. In some embodiments, the input is further configured to receive the first communication control rule in a diameter credit control answer message.
According to further embodiments, the first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the apparatus further comprises a processor configured to check whether at least the guaranteed number of firewall or network address translation function bindings are available.
According to further embodiments, the processor is further configured to reserve resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation in case at least the guaranteed number of firewall or network address translation function bindings are available.
According to further embodiments, the processor is further configured to check whether the first communication control rule comprises a binding pre-emption capability parameter in case at least the guaranteed number of firewall or network address translation function bindings are not available. According to further embodiments, the apparatus further comprises an output configured to report communication control rule activation failure in case the first communication con- trol rule does not comprise a binding pre-emption capability parameter .
According to some embodiments, the processor is further configured to check whether at least one second activated commu- nication control rule, for example a policy and charging rule, comprises a binding pre-emption vulnerability parameter and whether the at least one second activated communication control rule comprises a lower binding priority level than the first communication control rule in case the first commu- nication control rule comprises a binding pre-emption capa¬ bility parameter.
In some embodiments, one second activated communication con¬ trol rule comprises a binding pre-emption vulnerability para- meter and a lower binding priority level than the first com¬ munication control rule, and the processor is further configured to pre-empt at least one firewall or network address translation function binding associated with the one second activated communication control rule, and to reserve re- sources for the guaranteed number of firewall or network ad¬ dress translation function bindings as part of the first com¬ munication control rule activation.
In some embodiments, at least two second activated communica- tion control rules comprise a binding pre-emption vulnerabil¬ ity parameter and a lower binding priority level than the first communication control rule and the processor is further configured to compare binding priority levels of the at least two second activated communication control rules.
According to further embodiments, the processor is further configured to pre-empt at least one firewall or network ad- dress translation function binding associated with a second activated communication control rule with lowest priority level, and to reserve resources for the guaranteed number of firewall or network address translation function bindings as part of the first communication control rule activation.
In some embodiments, the processor is further configured to pre-empt firewall or network address translation function bindings associated with a second activated communication control rule such that the guaranteed number of firewall or network address translation function bindings comprised in the first communication control rule are available.
In some embodiments, the apparatus comprises a policy and charging enforcement function. In some embodiments, the appa ratus is located in a gateway general packet radio service support node or in a packet data network gateway.
According to some embodiments the first communication control rule comprises a policy and charging rule. According to some embodiments the second communication control rule comprises a policy and charging rule. According to some embodiments the communication control parameter rule comprises a policy and charging rule parameter.
According to a third aspect of the invention, there is pro¬ vided an apparatus comprising an output configured to send a first communication control rule, for example a policy and charging rule, to a policy and charging enforcement function, the rule comprising at least one communication control rule parameter, wherein the communication control rule is associated with controlling firewall or network address transla¬ tion function policy. According to some embodiments, the at least one communication control rule parameter comprises a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the communication control rule, a binding pre-emption vulnerability of the communication control rule, or a binding priority level of the communication control rule.
In some embodiments, the apparatus comprises a policy and charging rules function.
According to some embodiments the first communication control rule comprises a policy and charging rule. According to some embodiments the second communication control rule comprises a policy and charging rule. According to some embodiments the communication control parameter rule comprises a policy and charging rule parameter.
According to a fourth aspect of the invention, there is pro¬ vided a system comprising an apparatus of any of claims 18-36 and an apparatus of any of claims 37-40.
According to a fifth aspect of the invention, there is pro¬ vided a computer program product comprising code means adapted to perform all the steps of any of claims 1 to 17 when the program is run on a processor.
Embodiments of the present invention may have one or more of following advantages: defining a new NAT/firewall policy architecture in 3GPP simple support for NAT/firewall policies
enabling prioritized resource management BRIEF DESCRIPTION OF DRAWINGS
Embodiments of the present invention are described below with reference to the accompanying drawings, which are not neces¬ sarily drawn to scale, wherein:
Figure 1 illustrates a reference architecture for a case where NAT and/or firewall is invoked between a user equipment (UE) and the IMS domain, according to 3GPP TS 23.228.
Figure 2 illustrates a basic PCC reference architecture.
Figure 3 illustrates a basic PCC rule procedure according 3GPP TS 29.212.
Figures 4a, 4b and 4c illustrate a method according to an ex¬ emplary embodiment of the invention.
Figures 5a and 5b illustrate an apparatus according to an ex emplary embodiment of the invention.
Figure 6 illustrates an apparatus according to an exemplary embodiment of the invention.
Figure 7 illustrates a signaling flow when a default bearer is activated in a P-GW according to an exemplary embodiment of the invention.
Figure 8 illustrates a signaling flow related to an IMS voice call according to an exemplary embodiment of the invention. DETAILED DESCRIPTION OF SOME EMBODIMENTS
Some applications consume lots of NAT/firewall resources even though those applications may be of low priority. This may lead to a situation where e.g. low priority file transfer us¬ ing a file-sharing application (e.g. BitTorrent) consumes all the bindings in a gateway node and thus the gateway cannot forward traffic related to some other, more critical, appli¬ cation (s) . Even if a subscriber has some guaranteed resources available for NAT/firewall, subscriber may have concurrently open multiple applications where a low priority application is using all the resources, even though some of those re- sources should be given to the higher priority application.
The present invention defines policies depending on the ap¬ plications and not just on the subscribers or PDN connec¬ tions. In addition, the defined policies may allow pre- empting the already allocated resources, so that when e.g. resources are allocated to a low priority best-effort appli¬ cation, a high priority application having guaranteed resource may pre-empt some of the resources already given to the best-effort application. In summary, there are following problems, at least some of which this invention aims to solve :
missing NAT/firewall policy architecture in 3GPP
no way to define maximum and particularly guaranteed number of bindings per application
no way to define priority levels for the binding reser¬ vations, and no way to define which bindings should be released if there is need to allocate a new binding and all the binding resources have been already consumed The present invention is described herein with reference to particular non-limiting examples. Exemplary embodiments of the present invention will be described more fully hereinaf¬ ter with reference to the accompanying drawings, in which some, but not all embodiments of the invention are shown. It is generally to be noted that, according to certain needs and constraints, all of the described alternatives may be pro¬ vided alone or in any conceivable combination (also including combinations of individual features of the various alterna- tives) . A person skilled in the art will appreciate that the invention is not limited to these examples, and may be more broadly applied.
In particular, the present invention and its embodiments are mainly described in relation to 3GPP specifications being used as non-limiting examples for network configurations. As such, the description of the embodiments given herein specifically refers to terminology which is directly related there¬ to. Such terminology is only used in the context of the pre- sented non-limiting examples, and does naturally not limit the invention in any way. Rather, any other network configuration or implementation may also be utilized as long as compliant with the features described herein.
The invention is generic for all NAT variants, so the same invention can be applied for e.g. NAT44 and NAT64.
The firewall/policy architecture according to the invention may comprise the following nodes: - PCRF 200, which defines the NAT/firewall policies for
3GPP nodes in addition to other policy control.
PCEF 100, which implements the enforcement of
NAT/firewall policies and other policies given by PCRF 200. PCEF 100 is one of the functions of a user plane gateway 300, e.g. GGSN or P-GW.
Actual NAT/firewall rules may be defined as extensions to the existing PCC rules of the 3GPP PCC architecture. Particular¬ ly, the following new parameters may be added to the existing PCC rule (s) :
Maximum number of NAT/firewall bindings
Guaranteed number of NAT/firewall bindings
- Binding Pre-emption Capability (BPC) of PCC rule
Binding Pre-emption Vulnerability (BPV) of PCC rule Binding Priority Level (BPL) of PCC rule
These new PCC rule parameters may be passed to the PCEF 100 from the PCRF 200 as a part of the new Gx interface applica¬ tion attribute-value-pairs (AVPs) when a PCC rule is in¬ stalled or modified by the PCRF 200, as in Figure 3. These new PCC rule parameters may also be defined in local PCC rules, which are activated based on the rulebases installed by the PCRF 200. When the initial PCC rulebase or PCC rules are installed as part of the PDN connection activation, PCRF 200 may also enable/disable NAT, and depending on this infor¬ mation, the binding policies in the PCC rule may be applied to NAT or firewall function in the PCEF 100.
Alternatively, these NAT/firewall rules may be defined as separate NAT/firewall rules, instead of as extensions to the existing PCC rules. The invented method applies also in this case. For the sake of simplicity, in the following, the terms "PCC rule" and "PCC rule parameter" is used, but according to the invention they may as well be replaced with the terms "NAT/firewall rule" and "NAT/firewall rule parameter".
The invention defines a new NAT/firewall policy architecture, where NAT/firewall policies are controlled by the PCRF 200, which handles all the Quality of Service (QoS) and charging policies in the 3GPP architecture. The benefit of this ap¬ proach is that support for NAT/firewall policies may be done by adding a few new AVPs in the Gx interface. If local PCC rules are used, then only the PCC rule configuration in the PCEF 100 requires changes. Having common node for handling all policies allows having synergies when making the policy decisions.
Middlebox Communication working group (MIDCOM) defined architecture may also deployed. PCRF 200 may install NAT/firewall policies to the PCEF 100, which may then use the MIDCOM pro¬ tocol to define the actual NAT/firewall rules for the user plane function where NAT or firewall function is implemented.
Invention defines maximum and guaranteed number of bindings per PCC rule. This may allow more granular resource manage- ment than the prior art solutions, which allocated bindings per subscriber or per PDN connection. It may be possible to define that e.g. subscriber may have one guaranteed binding per for e-mail traffic, while the HTTP traffic may have maxi¬ mum 16 concurrent bindings active without any guaranteed num- ber of bindings.
For a guaranteed number of bindings, the defined number of bindings may be reserved when the PCC rule is activated (see below) . When a new binding is required, then maximum number of bindings of the PCC rule defines whether a new binding can be reserved.
Figures 4a, 4b and 4c illustrate some examples of the method according to the invention. In one embodiment, the PCEF 100 may receive (step SI) a request to activate a PCC rule, where the rule may comprise at least one PCC rule parameter. In further embodiments, the PCEF 100 may check whether the PCC rule requires guaranteed number of bindings, (step S2) . If guaranteed bindings are required, then PCEF 100 may reserve (step S3a) them when the PCC rule is activated. If there are not enough bindings available, PCEF 100 may check the binding pre-emption capability (BPC) value of the PCC rule (step S3b) . If BPC is not defined, then the PCC rule activation may fail. If BPC is defined, the PCEF 100 may check if there are any binding reservations done by other PCC rules where the binding pre-emption vulnerability (BPV) value indicates that its bindings can be pre-empted and if those PCC rules have lower priority (BPL) than the new PCC rule (step S4b) . If that is not the case, then the PCC rule activation may fail and the PCEF 100 may report PCC rule activation failure (step S4a) . Otherwise the binding (s) reserved by the other PCC rule may be released and allocated to the new PCC rule (step S5b) . If pre-emption is possible for multiple PCC rules, then BPL may be used to select the PCC rule with the lowest priority (steps S5a and S6a) . Pre-empting the other PCC rule may re¬ lease enough resource allocations done as part of the activa¬ tion of the other PCC rule for the "first" PCC rule. In one example, the other already activated PCC rule has 1000 bind¬ ings. In addition, there are currently 100 unallocated re¬ sources for bindings. If the new PCC requires 1000 guaranteed bindings, then pre-emption may release resources reserved for 900 bindings of the other PCC rule and the rest is taken from the unallocated resources.
If PCC rule activation fails at any point of the method, the PCEF 100 may report this to the PCRF 200 according to the section 4.5.12 of 3GPP TS 29.212 (e.g. version 11.0.1): If the installation/activation of one or more PCC rules fails using a PULL mode (i.e. the PCRF 200 installs/activates a rule using a CCA command) the PCEF 100 may send the PCRF 200 a new CCR command and include the Rule-Failure-Code AVP .
The same pre-emption method is applied also when a new bind¬ ing needs to be activated for the PCC rule, i.e. there are no free guaranteed level bindings available in the PCC rule, but the number of bindings does not exceed the maximum number of bindings of the PCC rule. The main difference is that if the new binding cannot be reserved, then the PCC rule may remain active .
The PCEF 100, as illustrated in Figures 5a and 5b, may com¬ prise an input 101 configured to receive a request to acti- vate a PCC rule. The PCEF may further comprise a memory 102 configured to store the PCC rule, a processor 103 configured to check whether a guaranteed number of firewall or network address translation function bindings are available, and an output 104 configured to report PCC rule activation failure in case the PCC rule cannot be activated. The PCEF 100 may be located in a user plane gateway 300, e.g. in a GGSN or in a PDN-GW.
The PCRF, as illustrated in Figure 6, may comprise an output 201 configured to send a PCC rule to a PCEF 100. The PCRF 200 may further comprise an input configured to receive a failure report from the PCEF 100.
The processor 103 may comprise a central processing unit
(CPU) or any other means for processing. The input 101 may comprise a receiver or any other means for receiving. The output 104, 201 may comprise a transceiver or any other means for transmitting. The processor 103, the memory 102, the in- put 101, and the output 104 may exchange information over an internal interface of the PCEF 100.
The input 101 and the output 104 of the PCEF 100 may be func¬ tionalities running on the processor 103 of the PCEF 100 or may alternatively be separate functional entities or means.
The input 101 and the output 104, 201 may also be implemented as integral transceivers or may be implemented e.g. as physi¬ cal transmitters/receivers for transceiving via the air in¬ terface, as routing entities for sending/receiving data pack- ets in a PS (packet switched) network, or as any suitable combination thereof.
The processor 103 may be configured to process various data inputs and to control input 101 and the output 104. The appa- ratus 100, 200 may further comprise a memory that may serve for storing code means for carrying out e.g. the methods ac¬ cording to the examples of the present invention, e.g. when run e.g. on the processor 103. According to all example embodiments, the PCC rule requested to be activated may be associated with controlling firewall or network address translation function policy and comprise at least one policy and charging rule parameter. The parame¬ ter may be e.g. a maximum number of firewall or network address translation function bindings for an application, a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of the policy and charging rule, a binding pre¬ emption vulnerability of the policy and charging rule, or a binding priority level of the policy and charging rule.
An example of a signaling flow when a default bearer is acti- vated in a P-GW 300 according to the invention is shown in
Figure 7. A serving gateway (S-GW) 400 may request a new de¬ fault bearer in the P-GW 300. The P-GW 300 may then send an initial CCR message to the PCRF 200 in order to receive poli¬ cies, including the NAT/firewall policies. The CCA message returned from the PCRF 200 may include PCC rules or PCC rule- bases which define the policies. The P-GW 300 may then acti¬ vate the PCC rules for the default bearer and make binding reservations according to the NAT/firewall policies. Default bearer activation may be completed when the P-GW 300 returns create session response to the S-GW 400.
Figure 8 shows an example of a signaling flow related to an IMS voice call. The IMS system, which corresponds to an AF 500 in the PCC architecture, may send a request to a PCRF 200 indicating that an IMS voice call is required. The PCRF 200 may send a Re-Auth-Request (RAR) message to a P-GW 300, con¬ taining a PCC rule which conventionally triggers dedicated bearer activation. If NAT is enabled for the PDN connection, this PCC rule may have additional NAT policies, which typi- cally define guaranteed NAT bindings for the voice media and BPC enabled to indicate that the voice call may pre-empt oth¬ er less important NAT bindings. If NAT is not enabled, but firewall is enabled, the PCC rule may define firewall poli¬ cies for the voice call. The P-GW 300 may create a new dedi- cated bearer for the voice call and it may also make the re¬ quired binding reservations.
One having ordinary skill in the art will readily understand that the invention as discussed above may be practiced with steps in a different order, and/or with hardware elements in configurations which are different than those which are dis¬ closed. Therefore, although the invention has been described based upon these preferred embodiments, it would be apparent to those of skill in the art that certain modifications, var¬ iations, and alternative constructions would be apparent, while remaining within the scope of the invention.

Claims

Claims
1. A method for controlling firewall or network address translation function comprising:
receiving (SI) at a policy and charging enforcement function a request to activate a first communication control rule, said rule comprising at least one communication control rule parameter;
wherein said communication control rule is associated with controlling firewall or network address translation function policy.
2. The method of claim 1, wherein said at least one communi¬ cation control rule parameter comprises - a maximum number of firewall or network address transla¬ tion function bindings for an application,
a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of said communication control rule,
a binding pre-emption vulnerability of said communica¬ tion control rule, or
a binding priority level of said communication control rule .
3. The method of claim 1 or 2, further comprising:
storing said first communication control rule.
4. The method of any of preceding claims, further comprising: receiving (SI) said first communication control rule from a policy and charging rules function.
5. The method of any of preceding claims, wherein said first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the method further comprises:
checking (S2) whether at least said guaranteed number of firewall or network address translation function bindings are available .
6. The method of claim 5, further comprising:
reserving (S3a) resources for said guaranteed number of firewall or network address translation function bindings as part of said first communication control rule activation in case at least said guaranteed number of firewall or network address translation function bindings are available.
7. The method of claim 5, further comprising:
checking (S3b) whether said first communication control rule comprises a binding pre-emption capability parameter in case at least said guaranteed number of firewall or network address translation function bindings are not available.
8. The method of claim 7, further comprising:
reporting (S4a) communication control rule activation failure in case said first communication control rule does not comprise a binding pre-emption capability parameter.
9. The method of claim 7, further comprising:
checking (S4b) whether at least one second activated communication control rule comprises a binding pre-emption vulnerability parameter and whether said at least one second activated communication control rule comprises a lower bind¬ ing priority level than said first communication control rule in case said first communication control rule comprises a binding pre-emption capability parameter.
10. The method of claim 9, wherein one second activated com¬ munication control rule comprises a binding pre-emption vulnerability parameter and a lower binding priority level than said first communication control rule and the method further comprises :
pre-empting (S5b) at least one firewall or network ad¬ dress translation function binding associated with said one second activated communication control rule, and
reserving resources for said guaranteed number of fire¬ wall or network address translation function bindings as part of said first communication control rule activation.
11. The method of claim 9, wherein at least two second acti¬ vated communication control rules comprise a binding pre¬ emption vulnerability parameter and a lower binding priority level than said first communication control rule and the me¬ thod further comprises:
comparing (S5a) binding priority levels of said at least two second activated communication control rules.
12. The method of claim 11, further comprising:
pre-empting (S6a) at least one firewall or network ad¬ dress translation function binding associated with a second activated communication control rule with lowest priority level, and
reserving resources for said guaranteed number of fire¬ wall or network address translation function bindings for activating said first communication control rule.
13. The method of claim 10 or 12, further comprising:
pre-empting firewall or network address translation function bindings associated with a second activated communi¬ cation control rule such that said guaranteed number of fire¬ wall or network address translation function bindings com- prised in said first communication control rule are availa¬ ble .
14. The method of any of preceding claims, wherein the commu- nication control rule comprises a policy and charging rule or a firewall or network address translation function rule.
15. An apparatus (100) comprising:
an input (101) configured to receive a request to acti¬ vate a first communication control rule, said rule comprising at least one communication control rule parameter;
wherein said communication control rule is associated with controlling firewall or network address translation function policy.
16. The apparatus (100) of claim 15, wherein said at least one communication control rule parameter comprises a maximum number of firewall or network address transla¬ tion function bindings for an application,
a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of said communication control rule,
a binding pre-emption vulnerability of said communica¬ tion control rule, or
a binding priority level of said communication control rule .
17. The apparatus (100) of claim 15 or 16, further compris ing :
a memory (102) configured to store said first communication control rule.
18. The apparatus (100) of any of claims 15 to 17, wherein said input (101) is further configured to receive said first communication control rule from a policy and charging rules function (200) .
19. The apparatus (100) of any of preceding claims, wherein said first communication control rule comprises a guaranteed number of firewall or network address translation function bindings parameter and the apparatus (100) further comprises a processor (103) configured to check whether at least said guaranteed number of firewall or network address trans¬ lation function bindings are available.
20. The apparatus (100) of claim 19, wherein said processor (103) is further configured to reserve resources for said guaranteed number of firewall or network address translation function bindings as part of said first communication control rule activation in case at least said guaranteed number of firewall or network address translation function bindings are available.
21. The apparatus (100) of claim 19, wherein said processor (103) is further configured to check whether said first com¬ munication control rule comprises a binding pre-emption capability parameter in case at least said guaranteed number of firewall or network address translation function bindings are not available.
22. The apparatus (100) of claim 21, further comprising:
an output (104) configured to report communication con¬ trol rule activation failure in case said first communication control rule does not comprise a binding pre-emption capabil¬ ity parameter.
23. The apparatus (100) of claim 21, wherein said processor (103) is further configured to check whether at least one second activated communication control rule comprises a bind¬ ing pre-emption vulnerability parameter and whether said at least one second activated communication control rule com¬ prises a lower binding priority level than said first commu- nication control rule in case said first communication control rule comprises a binding pre-emption capability parame¬ ter .
24. The apparatus (100) of claim 23, wherein one second acti¬ vated communication control rule comprises a binding pre¬ emption vulnerability parameter and a lower binding priority level than said first communication control rule, and the processor (103) is further configured
to pre-empt at least one firewall or network address translation function binding associated with said one second activated communication control rule, and
to reserve resources for said guaranteed number of fire¬ wall or network address translation function bindings as part of said first communication control rule activation.
25. The apparatus (100) of claim 23, wherein at least two second activated communication control rules comprise a bind¬ ing pre-emption vulnerability parameter and a lower binding priority level than said first communication control rule and the processor (103) is further configured to compare binding priority levels of said at least two second activated commu¬ nication control rules.
26. The apparatus (100) of claim 25, wherein the processor (103) is further configured
to pre-empt at least one firewall or network address translation function binding associated with a second activated communication control rule with lowest priority level, and
to reserve resources for said guaranteed number of fire¬ wall or network address translation function bindings as part of said first communication control rule activation.
27. The apparatus (100) of claim 24 or 26, wherein the pro¬ cessor (103) is further configured to pre-empt firewall or network address translation function bindings associated with a second activated communication control rule such that said guaranteed number of firewall or network address translation function bindings comprised in said first communication control rule are available.
28. The apparatus (100) of any of claims 15-27, wherein the communication control rule comprises a policy and charging rule or a firewall or network address translation function rule .
29. An apparatus (200) comprising:
an output (201) configured to send first communication control rule to a policy and charging enforcement function (100), said rule comprising at least one communication control rule parameter;
wherein said communication control rule is associated with controlling firewall or network address translation function policy.
30. The apparatus (200) of claim 29, wherein said at least one communication control rule parameter comprises a maximum number of firewall or network address transla¬ tion function bindings for an application,
a guaranteed number of firewall or network address translation function bindings for an application, a binding pre-emption capability of said communication control rule,
a binding pre-emption vulnerability of said communica¬ tion control rule, or
a binding priority level of said communication control rule .
31. The apparatus (200) of claim 29 or 30, wherein the commu¬ nication control rule comprises a policy and charging rule or a firewall or network address translation function rule.
32. A system comprising an apparatus (100) according to any of claims 15 to 28 and an apparatus (200) according to any of claims 29 to 31.
33. A computer program product comprising code means adapted to perform all the steps of any of claims 1 to 14 when the program is run on a processor.
PCT/EP2011/058928 2011-05-31 2011-05-31 Communication control in communication networks Ceased WO2012163405A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/EP2011/058928 WO2012163405A1 (en) 2011-05-31 2011-05-31 Communication control in communication networks

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2011/058928 WO2012163405A1 (en) 2011-05-31 2011-05-31 Communication control in communication networks

Publications (1)

Publication Number Publication Date
WO2012163405A1 true WO2012163405A1 (en) 2012-12-06

Family

ID=44627861

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2011/058928 Ceased WO2012163405A1 (en) 2011-05-31 2011-05-31 Communication control in communication networks

Country Status (1)

Country Link
WO (1) WO2012163405A1 (en)

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Policy and Charging Control over Gx reference point (Release 7)", 3GPP STANDARD; 3GPP TS 29.212, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V7.11.0, 18 December 2009 (2009-12-18), pages 1 - 47, XP050401204 *
"Digital cellular telecommunications system (Phase 2+); Universal Mobile Telecommunications System (UMTS); LTE; Policy and charging control signalling flows and Quality of Service (QoS) parameter mapping (3GPP TS 29.213 version 10.1.0 Release 10)", TECHNICAL SPECIFICATION, EUROPEAN TELECOMMUNICATIONS STANDARDS INSTITUTE (ETSI), 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS ; FRANCE, vol. 3GPP CT 3, no. V10.1.0, 1 April 2011 (2011-04-01), XP014065089 *
"Protocol at the interface between the policy decision physical entity (PD-PE) and the policy enforcement physical entity (PE-PE) (Rw interface): Diameter; Q.3303.3 (05/08)", ITU-T STANDARD, INTERNATIONAL TELECOMMUNICATION UNION, GENEVA ; CH, no. Q.3303.3 (05/08), 22 May 2008 (2008-05-22), pages 1 - 58, XP017466787 *
"Telecoms & Internet converged Services & Protocols for Advanced Networks (TISPAN); NAT Traversal feasibility study report; Draft ETSI TR 187 008", IEEE, LIS, SOPHIA ANTIPOLIS CEDEX, FRANCE, no. V0.0.16, 1 December 2007 (2007-12-01), XP014040980, ISSN: 0000-0001 *

Similar Documents

Publication Publication Date Title
US9661082B2 (en) Token related apparatuses for deep packet inspection and policy handling
US8601125B2 (en) Service processing method and system, and policy control and charging rules function
EP2543163B1 (en) Methods, systems, and computer readable media for enhanced service detection and policy rule determination
US8750825B2 (en) Methods, systems, and computer readable media for inter-carrier roaming cost containment
US20140153391A1 (en) Method for Policy Control and Method for Bearer Control as Well as Corresponding Servers, Systems and Computer Programs
US9473928B2 (en) Methods, systems, and computer readable media for policy-based local breakout (LBO)
US9137843B2 (en) Method and node for controlling bearer related resources as well as a corresponding system and computer program
EP2802170A1 (en) Method, system and device for service rate control
KR102026140B1 (en) Service processing method, PCRF and service processing system
JP2015507897A (en) Handling authorization requests for packet-based services in cellular networks
CN104205727B (en) Session Termination in Mobile Packet Core Networks
WO2017173897A1 (en) Application-based policy and charging control method, apparatus and system
WO2012163405A1 (en) Communication control in communication networks
CN104219783A (en) Session redirection method and equipment
KR102315347B1 (en) HSS(Home Subscriber Server) and HSS control method
US9794324B2 (en) Application function dependent policy control
US9319273B2 (en) Policy coordination between policy enforcement points
EP2904751B1 (en) Event based quality of service adjustment
JP2016154389A (en) Session termination in mobile packet core network
WO2015147708A1 (en) Allocated bitrate offering

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11729268

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11729268

Country of ref document: EP

Kind code of ref document: A1