Adaptive Firewall Configuration via User Equipment Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring firewalls in local area communication networks, especially home gateways, is challenging due to the need for customized rules that balance security and service operation, often requiring advanced computing knowledge and lacking adaptive solutions for specific user equipment connected to the network.

Innovation Solution

A method that analyzes user equipment characteristics in the network to automatically generate and update firewall configuration rules based on a predetermined model, allowing for tailored and adaptive security settings, with administrator validation and regular monitoring to ensure accurate and efficient configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of firewall rules is performed, then customized security rules can be created for specific user equipment, but it requires advanced computing knowledge and is complex to operate

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The firewall configuration system automatically performs self-service by detecting user equipment characteristics and generating appropriate configuration rules without requiring manual intervention. The system analyzes equipment types, services, and network behavior to autonomously create customized firewall rules, eliminating the need for administrators to have advanced computing knowledge while maintaining reliable security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual configuration process with an automated information processing system. Instead of manually analyzing equipment characteristics and creating rules, the system uses automatic detection, analysis algorithms, and rule generation mechanisms to substitute the manual configuration process, thereby reducing operational complexity while maintaining security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If predefined configuration modes are used, then the firewall can be easily configured with simple modes, but it only allows global configuration for all services and cannot adapt to specific user equipment features

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidconfiguration adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by creating customized firewall configuration rules specific to each user equipment rather than applying a single global configuration to all devices. The system analyzes individual equipment characteristics such as device type, running services, and network behavior to generate equipment-specific rules, thereby achieving both ease of operation through automation and adaptability through customization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The firewall configuration is made dynamic by continuously monitoring user equipment characteristics and automatically updating configuration rules when changes are detected. The system adapts to changing network conditions, equipment states, and service deployments in real-time, transitioning from static predefined modes to dynamic adaptive configuration that maintains both simplicity and versatility.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strict firewall rules are applied, then host equipment becomes more resistant to attacks, but the operation of services deployed by client equipment may be worsened

Engineering Contradiction:
Improveattack resistanceVSAvoidservice operation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent dynamically adjusts firewall rule parameters based on analyzed characteristics of user equipment and observed network behavior. Instead of applying uniformly strict rules, the system modifies rule parameters such as port access, protocol restrictions, and connection limits according to equipment type, service requirements, and legitimate traffic patterns, thereby maintaining attack resistance while preserving service operation productivity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms by monitoring service traffic patterns and legitimate network behavior, then using this information to adjust firewall rule strictness. The feedback loop allows the system to identify and permit legitimate service operations while maintaining strict filtering against actual threats, thereby balancing attack resistance with service productivity through continuous adaptation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11310111B2Method for configuring a firewall equipment in a communication network, method for updating a configuration of a firewall equipment, and corresponding device, access equipment, firewall equipment and computer programs
Publication Date: 2022.04.19 ORANGE SA
  • US11310111B2 patent drawing
  • US11310111B2 patent drawing
  • US11310111B2 patent drawing

AI summary

A method for configuring a firewall equipment in a first communication network managed by an access equipment for accessing a second communication network. Such a method implements: obtaining characteristic information of a user equipment in the first network by analyzing its active interfaces in the network; generating configuration rules for configuring the firewall equipment on the basis of the obtained features and of a predetermined configuration model; and transmitting, to the firewall equipment, an update command message to update a configuration, including the determined configuration rules.