Dynamic Firewall Rule Configuration for Mobile IP Handovers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 3G and beyond networks, firewalls are not configured to appropriately forward traffic during mobile IP handovers, leading to blocked legitimate traffic due to unupdated packet filter rules, as the change in IP addresses is not efficiently managed across the network.

Innovation Solution

A method and device for configuring firewalls using mobility reports and session reports to update, add, or modify firewall policies, ensuring legitimate traffic can be routed dynamically through the network by a firewall controller associated with the Policy Control and Charging Rules Function (PCRF).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet filter rules are configured statically in firewalls for 3G networks, then network security and access control are maintained, but legitimate traffic is blocked during mobile IP handovers due to unupdated IP addresses

Engineering Contradiction:
Improvenetwork securityVSAvoidtraffic forwarding capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic firewall rule configuration by introducing a firewall controller that receives mobility reports from the GGSN and automatically updates packet filter rules in response to mobile IP handovers. The system transitions from static, pre-configured firewall rules to dynamic rules that adapt in real-time to changing IP addresses, thereby maintaining both security and adaptability during mobility events

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the GGSN monitors mobile station handovers and sends mobility reports to the firewall controller. The controller processes this feedback information and automatically configures updated firewall rules, creating a closed-loop system that continuously adapts to network changes while maintaining security policies

Inventive Principle:
Principle #23Feedback

2Productivity

If firewall rules are updated dynamically during mobile IP handovers, then legitimate traffic flows are maintained, but network complexity increases due to additional control mechanisms

Engineering Contradiction:
Improvetraffic flow continuityVSAvoidfirewall configuration system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall controller as an intermediary component between the GGSN and the firewall. This mediator receives mobility reports from the GGSN, processes the handover information, and automatically generates updated firewall rules. By placing this intelligent intermediary in the control plane, the system achieves dynamic adaptation without complicating the data plane forwarding operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates firewall control functions into distinct components: the GGSN handles mobility detection, the firewall controller handles rule generation and management, and the actual firewalls execute filtering operations. This segmentation allows each component to specialize in its function, reducing overall system complexity while enabling dynamic rule updates

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual firewall configuration is used for each mobile station, then security policies are precisely controlled, but configuration time and operational overhead increase significantly

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidfirewall configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service automation where the firewall controller automatically generates and configures firewall rules based on mobility reports received from the GGSN. Instead of requiring manual configuration for each mobile station, the system autonomously detects handovers, generates appropriate security rules, and applies them to firewalls, eliminating configuration delays and reducing operational overhead while maintaining precise security policy enforcement

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1971101B1A method , a device for configuring at least one firewall and a system comprising such device
Publication Date: 2018.11.21 NOKIA SIEMENS NETWORKS GMBH & CO KG
  • EP1971101B1 patent drawingFigure 1
  • EP1971101B1 patent drawingFigure 2
  • EP1971101B1 patent drawingFigure 3A

AI summary

A method and a device to configure at least one firewall are provided comprising the steps of (i) transmitting at least one mobility report to a firewall controller; (ii) transmitting at least one session report to the firewall controller; and (iii) configuring the at least one firewall according to the information obtained by the at least one mobility report and by the at least one session report.