×

Firewall control system based on a next generation network service and method thereof

  • US 7,987,503 B2
  • Filed: 04/23/2007
  • Issued: 07/26/2011
  • Est. Priority Date: 07/30/2005
  • Status: Expired due to Fees
First Claim
Patent Images

1. A firewall control system based on a Next Generation Network (NGN) service, the system comprising:

  • an Application Proxy module including an Application-proxy-based Firewall function located in an NGN Service Control Function (SCF) device, for resolving an application layer signalling, performing a security inspection of a signalling flow, and determining requirements of a service media flow on security level;

    a Policy Decision Functional entity (PDF), for mapping the requirements of the service media flow on security level to controlment of the service media flow on security level, according to a stored policy and the requirements of the service media flow on security level provided by the Application Proxy module; and

    a firewall function module configured in a Border Gateway Function (BGF) device, for performing a security inspection of the service media flow passing by, according to the controlment of the service media flow on security level control provided by the PDF;

    wherein the firewall function module comprises;

    a packet filtering mode selection module, for determining a working mode of firewall packet filtering for a security inspection of the service media flow, according to the controlment of the media flow on security level provided by the PDF; and

    a packet filtering processing module including configured firewall functions with various working modes of firewall packet filtering, wherein the configured firewall functions are initiated under the control of the packet filtering mode selection module and used for performing a security inspection of a corresponding service; and

    wherein the packet filtering mode selection module is further used for initiating a corresponding Packet-filter-based Firewall processing function in a corresponding packet filtering processing module.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×