Selective Firewall Synchronization in Mobile Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of data connections and GTP context information in mobile networks, particularly with the rise of M2M and IoT devices, leads to increased resource load on network nodes, affecting bandwidth and latency, and poses challenges in protecting against attacks and unwanted network access.
Innovation Solution
A method and data communication system that selectively synchronizes data connection information between firewalls in an IP-based core network, especially during handovers, ensuring that only the relevant firewall receives the necessary data connection information, thereby optimizing resource usage and maintaining secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data connection information is stored in all firewalls for security checks, then security protection is improved, but resource load on network nodes increases
Solution Approach 1:
The patent divides the firewall system into multiple distributed firewalls, each responsible for specific data connections. Instead of centralizing all GTP context information in one firewall, the system segments the information storage and processing across multiple firewalls based on their respective responsibilities for different data connections, thereby reducing the resource load on any single node while maintaining security
Solution Approach 2:
Each firewall stores and processes only the data connection information relevant to its specific responsibilities. The patent implements local quality by ensuring that firewall A holds information for data connections it is responsible for, and firewall B holds information for different data connections, optimizing resource usage by avoiding redundant storage across all firewalls
2Reliability
If data connection information is synchronized between all firewalls, then security is improved, but bandwidth consumption increases
Solution Approach 1:
The patent extracts and transmits only the specific data connection information that is necessary for the handover process between firewalls. Instead of synchronizing all GTP context information across all firewalls, the system extracts and transfers only the relevant portions needed for maintaining security during handover, thereby reducing bandwidth consumption
Solution Approach 2:
The patent performs preliminary identification of which data connection information needs to be synchronized before actual transmission occurs. By determining in advance which firewalls need which information based on their responsibilities, the system avoids unnecessary data transmission and reduces overall bandwidth consumption while maintaining security
3Reliability
If all firewalls process every data packet for security checks, then protection against attacks is improved, but processing time increases
Solution Approach 1:
The patent segments the data packet processing responsibility among multiple firewalls based on their assigned data connections. Each firewall processes only the packets for its responsible connections rather than all packets, significantly reducing processing time while maintaining comprehensive security coverage through the distributed firewall architecture
Solution Approach 2:
The patent introduces a coordination mechanism that acts as an intermediary to direct data packets to the appropriate firewall for processing. This mediator component ensures that packets are routed to the correct firewall that has the relevant GTP context information, avoiding unnecessary processing by other firewalls and reducing overall processing time
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for selectively synchronizing data connection information between firewalls (110-130) of an IP-based core network (40) of a mobile network (160) and a data communication system (10) comprising a mobile network (160), which is configured to selectively transfer data connection information associated with the transferred data connection from the previous firewall (110) to a new firewall (120) of an IP-based core network (40) of the mobile network (160) after a handover of an ongoing data connection established between a mobile terminal (20) and a target device (50), i.e., after a data connection handover.