Dynamic Firewall Rule Configuration for Mobile IP Handovers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 3G and beyond networks, firewalls are not configured to appropriately forward traffic during mobile IP handovers, leading to blocked legitimate traffic due to unupdated packet filter rules, as the change in IP addresses is not efficiently managed across the network.
Innovation Solution
A method and device for configuring firewalls using mobility reports and session reports to update, add, or modify firewall policies, ensuring legitimate traffic can be routed dynamically through the network by a firewall controller associated with the Policy Control and Charging Rules Function (PCRF).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet filter rules are configured statically in firewalls for 3G networks, then network security and access control are maintained, but legitimate traffic is blocked during mobile IP handovers due to unupdated IP addresses
Solution Approach 1:
The patent implements dynamic firewall rule configuration by introducing a firewall controller that receives mobility reports from the GGSN and automatically updates packet filter rules in response to mobile IP handovers. The system transitions from static, pre-configured firewall rules to dynamic rules that adapt in real-time to changing IP addresses, thereby maintaining both security and adaptability during mobility events
Solution Approach 2:
The system establishes a feedback loop where the GGSN monitors mobile station handovers and sends mobility reports to the firewall controller. The controller processes this feedback information and automatically configures updated firewall rules, creating a closed-loop system that continuously adapts to network changes while maintaining security policies
2Productivity
If firewall rules are updated dynamically during mobile IP handovers, then legitimate traffic flows are maintained, but network complexity increases due to additional control mechanisms
Solution Approach 1:
The patent introduces a firewall controller as an intermediary component between the GGSN and the firewall. This mediator receives mobility reports from the GGSN, processes the handover information, and automatically generates updated firewall rules. By placing this intelligent intermediary in the control plane, the system achieves dynamic adaptation without complicating the data plane forwarding operations
Solution Approach 2:
The system separates firewall control functions into distinct components: the GGSN handles mobility detection, the firewall controller handles rule generation and management, and the actual firewalls execute filtering operations. This segmentation allows each component to specialize in its function, reducing overall system complexity while enabling dynamic rule updates
3Reliability
If manual firewall configuration is used for each mobile station, then security policies are precisely controlled, but configuration time and operational overhead increase significantly
Solution Approach 1:
The system implements self-service automation where the firewall controller automatically generates and configures firewall rules based on mobility reports received from the GGSN. Instead of requiring manual configuration for each mobile station, the system autonomously detects handovers, generates appropriate security rules, and applies them to firewalls, eliminating configuration delays and reducing operational overhead while maintaining precise security policy enforcement
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A method and a device to configure at least one firewall are provided comprising the steps of (i) transmitting at least one mobility report to a firewall controller; (ii) transmitting at least one session report to the firewall controller; and (iii) configuring the at least one firewall according to the information obtained by the at least one mobility report and by the at least one session report.