Application-Aware Firewall Gateway for Secure Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current client/server communication methods face inefficiencies, including disabled local network operations, complex access policy management, and security vulnerabilities when traversing firewalls, particularly due to the need for multiple protocol processor plug-ins and lack of granular access control.

Innovation Solution

A secure communication framework that connects clients and server resources at the application level through a firewall, using a standardized platform with quarantine functions to ensure minimum software patch requirements and granular access policies, simplifying the development of protocol processor plug-ins and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network layer tunneling is used to traverse the firewall, then secure connection is achieved, but local network operations are disabled

Engineering Contradiction:
Improvesecure connectionVSAvoidlocal network operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments network operations into two distinct paths: application-layer connections for remote resources through the gateway server, and local network operations for accessing resources on the same network. This allows clients to maintain both secure remote access and local network functionality simultaneously without interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway server acts as an intermediary that handles application-layer connections through the firewall while allowing local network traffic to bypass the gateway. This mediator enables clients to access both remote resources securely and local resources directly, resolving the conflict between secure connection and local network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If application layer connection is used, then local network operations remain available, but complex protocol processor plug-ins are required for each resource

Engineering Contradiction:
Improvelocal network operationsVSAvoidprotocol processor plug-ins
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway server implements a universal protocol processing mechanism that can handle multiple application protocols (HTTP, HTTPS, FTP, SMTP, etc.) through a single standardized interface. This eliminates the need for separate protocol processor plug-ins for each resource type, as the gateway server provides multi-protocol support through its application-aware firewall capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the approach from requiring different protocol processors for each application to using a single protocol processor that adapts to different protocols through parameter configuration. The gateway server identifies the application protocol being used and applies appropriate firewall rules and access policies dynamically, reducing complexity while maintaining functionality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If VPN/RAS is used for firewall traversal, then packet inspection and filtering is possible, but complex or stateful protocols are difficult to handle

Engineering Contradiction:
Improvepacket inspection and filteringVSAvoidcomplex or stateful protocols
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway server serves as an intermediary that performs deep packet inspection and stateful protocol handling. Rather than relying on client-side VPN/RAS for these functions, the gateway server mediates all traffic, inspecting packets and managing protocol states centrally. This allows complex stateful protocols to be handled properly while maintaining security and filtering capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the mechanical VPN/RAS tunneling approach with an application-aware gateway server that uses intelligent protocol analysis and dynamic rule application. This substitution enables better handling of complex protocols through automated protocol identification and adaptive firewall rule enforcement, rather than relying on generic packet filtering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If multiple protocol processor plug-ins are developed for different resources, then specific resource access is enabled, but development complexity and access policy management increase

Engineering Contradiction:
Improvespecific resource accessVSAvoiddevelopment complexity and access policy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway server provides a universal access control mechanism that manages policies for multiple resources and protocols through a centralized system. Instead of requiring separate policy management for each protocol processor plug-in, the gateway server maintains a unified policy framework that applies to all resources, reducing development complexity while maintaining specific resource access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the functionality of multiple protocol processor plug-ins into a single gateway server that handles all protocols through unified application-aware processing. This consolidation combines resource access, protocol handling, and policy management into one system, reducing the number of components developers must create and maintain while preserving the ability to access specific resources with appropriate policies.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP1934768B1Providing consistent application aware firewall traversal
Publication Date: 2017.01.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP1934768B1 patent drawing

AI summary

Implementations of the present invention relate to a communication framework that is readily adaptable to a wide variety of resources intended to be accessible through a firewall. In general, a communication framework at a gateway server can provide a specific connection to a requested resource in accordance with a wide range of resource and/or network access policies. In one instance, a client requests a connection to a specific resource behind a firewall. The communication framework authenticates the connection, and quarantines the connection until determining, for example, that the client is using an appropriate resource features. If appropriately authenticated, the communication framework can pass control of the connection to an appropriately identified protocol plug-in processor, which facilitates a direct connection to the requested resource at an application layer of a communication stack.