GTP Firewall Device Policy Synchronization via Cloud Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual updates of IP addresses in IR.21 protocols compromise network security for roaming mobile devices, leading to stale addresses being granted access and new addresses being denied, as existing protocols fail to provide real-time synchronization of firewall rules and policies.

Innovation Solution

A cloud-based GTP GSN objects server registers GTP firewall devices with IR.21 records from multiple carriers, distributing updates in real-time to ensure that only authorized IP addresses are granted access, thereby synchronizing firewall rules and policies automatically across a data communication network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates of IP addresses in IR.21 protocols are used, then network administrators can control firewall rules, but network security is compromised due to stale IP addresses being granted access and new IP addresses being denied

Engineering Contradiction:
Improvenetwork securityVSAvoidtime delay in IP address updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a feedback mechanism where the GTP firewall device continuously monitors for updates to IP addresses in IR.21 records from carriers. When updates are detected, the device automatically receives and applies them in real-time, creating a closed-loop system that ensures firewall rules remain synchronized with current carrier IP address allocations, thereby maintaining network security without manual intervention delays

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The GTP firewall device is configured to automatically detect, receive, and apply updates to IP addresses in IR.21 records without requiring manual administrator intervention. The device autonomously manages its own firewall rule synchronization by continuously monitoring for updates from carriers and self-updating its authorization criteria, eliminating the time loss associated with manual update processes

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual updates of IP addresses are performed, then firewall rules can be adjusted, but false positives and false negatives occur in granting access to roaming devices

Engineering Contradiction:
Improveaccuracy of IP address authorizationVSAvoidoperational complexity of firewall management
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system establishes continuous feedback loops where the GTP firewall device monitors carrier IP address updates in real-time and automatically adjusts its authorization decisions. This ensures that access granting is based on current, accurate IP address information from IR.21 records, eliminating false positives (unauthorized access granted) and false negatives (authorized access denied) that occur with stale manual updates

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary automated update mechanism between carriers and the GTP firewall device. Instead of direct manual administrator intervention, the system uses automated protocols to mediate the transmission and application of IP address updates, improving measurement precision of authorization decisions while reducing operational complexity by eliminating manual processes

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time automatic synchronization of IP addresses is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcomplexity of GTP firewall device
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The GTP firewall device is designed with multi-functionality, combining traditional firewall capabilities with automated IP address update detection and synchronization functions. By integrating these diverse functions into a single device, the patent achieves real-time automatic synchronization that improves network security while minimizing the increase in device complexity through functional consolidation rather than adding separate dedicated systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10911935B1Automatically syncing GTP roaming firewall device policies over a data communication network for network security over mobile devices roaming data services on a carrier network
Publication Date: 2021.02.02 FORTINET INC
  • US10911935B1 patent drawing
  • US10911935B1 patent drawing
  • US10911935B1 patent drawing

AI summary

A GTP firewall device registers with a cloud-based GTP GSN objects server to receive IR.21 records for each of a plurality of carriers for which roaming data services are authorized for roaming mobile devices of the plurality of carriers. The cloud-based GTP GSN objects server distributes IR.21 records and updates to the plurality of carriers. The GTP firewall device receives substantially real-time updates to the IP addresses for IR.21 records of carriers from the cloud-based GTP GSN objects server. The updates are responsive to addition of new IP addresses or removal of deleted IP address by a carrier at an IR.21 IP address server, for subsequent authorizations.