Method and Apparatus for Virtual Firewalling in a Wireless Communication Network
First Claim
1. A method of virtual firewall management performed at a first control node in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said method comprising:
- detecting a handover event involving handover of a wireless device from a first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; and
responsive to said detecting, initiating a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into the CN.
1 Assignment
0 Petitions
Accused Products
Abstract
This disclosure provides example details for apparatuses and methods that manage virtual firewalls in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN. The virtual firewalls process traffic for respective wireless devices supported by the network. For example, the virtual firewall associated with a given wireless device is maintained in the RAN at the RAN node supporting the device, and is migrated from that RAN node in response to detecting a handover event involving the device. Advantageously, migration may be “horizontal,” where the associated virtual firewall is moved between nodes in the RAN, or may be “vertical,” where the associated virtual firewall is moved from the RAN to the CN.
13 Citations
26 Claims
-
1. A method of virtual firewall management performed at a first control node in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said method comprising:
-
detecting a handover event involving handover of a wireless device from a first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; and responsive to said detecting, initiating a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into the CN. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A first control node configured for virtual firewall management in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said first control node comprising:
-
a communication interface configured for communicating with a first RAN node in the network; a processing circuit that is operatively associated with the communication interface and configured to; detect a handover event involving handover of a wireless device from-the first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; and responsive to said detecting, initiate a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into-the CN. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. A method of virtual firewall management performed at a first Radio Access Network, RAN, node operating in a RAN of a wireless communication network that further includes an associated Core Network, CN, said method comprising:
-
maintaining an associated virtual firewall for a wireless device served by the first RAN node; receiving transfer initiation signaling from a control node in the network, indicating that the associated virtual firewall is to be migrated, said migration being horizontally to a second RAN node in the network, or vertically to the CN; and transferring the associated virtual firewall in accordance with the transfer initiation signaling. - View Dependent Claims (22, 23)
-
-
24. A first Radio Access Network, RAN, node configured for virtual firewall management in a wireless communication network that further includes an associated Core Network, CN, said first RAN node comprising:
-
a communication interface configured for communicating with a control node in the network and with a wireless device served by the first RAN node; a processing circuit that is operatively associated with the communication interface and configured to; maintain an associated virtual firewall for the wireless device; receive transfer initiation signaling from the control node in the network, indicating that the associated virtual firewall is to be migrated, said migration being horizontally to a second RAN node in the network, or vertically to the CN; and transfer the associated virtual firewall in accordance with the transfer initiation signaling.
-
-
25. A method of virtual firewall management performed at a second Radio Access Network, RAN, node operating in a RAN of a wireless communication network that-further includes an associated Core Network, CN, said method comprising:
-
receiving an associated virtual firewall for a wireless device, from a first RAN node, or from an associated control node in the CN; the associated virtual firewall at the second RAN node for processing traffic for the wireless device according to the associated virtual firewall; and sending an indication of said activation to the first RAN node, or to the associated control node. - View Dependent Claims (26)
-
Specification