Method and apparatus for virtual firewall migration in a wireless communication network
First Claim
1. A method of virtual firewall management performed at a first control node in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said method comprising:
- detecting a handover event involving handover of a wireless device from a first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; and
responsive to said detecting, initiating a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into the CN;
said method further comprising selecting between horizontal migration or vertical migration of the associated virtual firewall based on evaluating at least one of mobility data for the wireless device and location data for the wireless device.
1 Assignment
0 Petitions
Accused Products
Abstract
This disclosure provides example details for apparatuses and methods that manage virtual firewalls in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN. The virtual firewalls process traffic for respective wireless devices supported by the network. For example, the virtual firewall associated with a given wireless device is maintained in the RAN at the RAN node supporting the device, and is migrated from that RAN node in response to detecting a handover event involving the device. Advantageously, migration may be “horizontal,” where the associated virtual firewall is moved between nodes in the RAN, or may be “vertical,” where the associated virtual firewall is moved from the RAN to the CN.
9 Citations
18 Claims
-
1. A method of virtual firewall management performed at a first control node in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said method comprising:
-
detecting a handover event involving handover of a wireless device from a first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; and responsive to said detecting, initiating a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into the CN; said method further comprising selecting between horizontal migration or vertical migration of the associated virtual firewall based on evaluating at least one of mobility data for the wireless device and location data for the wireless device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A first control node configured for virtual firewall management in a wireless communication network that includes a Core Network, CN, and an associated Radio Access Network, RAN, said first control node comprising:
-
a communication interface configured for communicating with a first RAN node in the network; a processing circuit that is operatively associated with the communication interface and configured to; detect a handover event involving handover of a wireless device from the first RAN node in the network to a second RAN node in the network, wherein an associated virtual firewall is maintained for the wireless device at the first RAN node; responsive to said detecting; initiate a migration of the associated virtual firewall from the first RAN node, said migration being a horizontal migration of the associated virtual firewall to the second RAN node, or being a vertical migration of the associated virtual firewall into the CN; and select between horizontal migration or vertical migration of the associated virtual firewall based on evaluating at least one of mobility data for the wireless device and location data for the wireless device. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18)
-
Specification