Application Identifier Firewall Rules for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized environments, traditional firewall rules based on physical network locations such as IP addresses and port numbers become ineffective due to dynamic application deployment, leading to complications in location-based firewall management.

Innovation Solution

Implementing a firewall service in a cloud computing environment that uses application identifier-based rulesets instead of location-based rules, where a firewall controller provides unique application identifiers and manages rules for one or more firewalls, allowing or blocking packets based on source and destination application identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional location-based firewall rules are used, then firewall management is simple in static environments, but firewall rules become ineffective and require frequent updates in virtualized environments with dynamic application deployment

Engineering Contradiction:
Improvefirewall rule effectivenessVSAvoidfirewall management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the identification parameter from static location-based identifiers (IP addresses, port numbers) to dynamic application-based identifiers. This allows firewall rules to remain effective despite changes in application location, as the rules now track applications rather than fixed network positions.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an application identifier as an intermediary between the application and the firewall system. This identifier acts as a stable reference that connects the dynamic application instance to the static firewall rule set, allowing the firewall to manage traffic based on application identity rather than transient location.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If application identifier-based rules are implemented, then firewall adaptability improves in virtualized environments, but system complexity increases due to application verification and identifier management

Engineering Contradiction:
Improvefirewall adaptability to dynamic deploymentVSAvoidapplication verification and identifier management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where applications automatically obtain application identifiers and register themselves with the firewall system. This automation reduces the manual complexity of tracking and managing application identifiers, as the system handles the verification and assignment processes without extensive human intervention.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If location-based firewall rules are used, then rule implementation is straightforward, but frequent rule updates are required as applications move between locations

Engineering Contradiction:
Improvefirewall rule implementationVSAvoidtime for frequent rule updates
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary action by assigning application identifiers to applications before they are deployed or moved. This pre-assignment ensures that firewall rules can be configured once based on application identity and will remain valid regardless of future location changes, eliminating the need for frequent rule updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250126097A1Firewall System With Application Identifier Based Rules
Publication Date: 2025.04.17 COMCAST CABLE COMM LLC
  • US20250126097A1 patent drawing
  • US20250126097A1 patent drawing
  • US20250126097A1 patent drawing

AI summary

A firewall service for a cloud computing environment is described that uses an application identifier-based ruleset to process data packets. An application identifier-based rule may provide an action to be taken on a received packet based on the source application identifier, the destination application identifier, and/or an identification token associated with the source application. A firewall controller may verify applications of the computing environment, provide unique application identifiers, and manage the application identifier rules for one or more firewalls of the computing environments.