Building Network Firewall for Multi-Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access control between multiple networks in a building setting is complex, especially when these networks can be accessed from outside, as existing solutions require multiple firewalls and extensive configuration, leading to inefficiencies and increased complexity.

Innovation Solution

A firewall system that connects to at least two local area networks and an external node, allowing three-way control of data traffic by establishing tunnels between networks using protocols like HTTPS/Websocket or VPN, and applying rules to allow or deny access based on source and destination addresses and protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple firewalls are deployed to control access between multiple networks, then access control security is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveaccess control securityVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple firewall functions into a single firewall device that can handle access control between multiple networks simultaneously. The firewall is configured with multiple network interfaces connected to different networks and can apply access rules to traffic between any combination of these networks, eliminating the need for separate firewalls for each network pair.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The firewall is designed with multi-functional capabilities to perform access control for multiple network combinations through a single device. It can identify traffic sources and destinations across different networks and apply appropriate access rules dynamically, making one firewall universal for managing access between multiple networks rather than requiring dedicated firewalls for each network pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple firewalls are used to control access between multiple networks, then access control coverage is improved, but the number of physical ports and hardware resources increase

Engineering Contradiction:
Improveaccess control coverageVSAvoidnumber of physical ports
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges the functionality of multiple firewalls into a single device with multiple network interfaces. Each interface connects to a different network, and the single firewall device can manage access control for all network combinations, reducing the total number of physical devices and ports required compared to deploying separate firewalls for each network pair.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The firewall device is designed with universal access control capabilities that allow it to monitor and control traffic between any combination of connected networks through its multiple interfaces. This multi-functional design enables one device to provide the access control coverage that would otherwise require multiple dedicated firewalls, thereby reducing hardware resource requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If traditional firewall configurations are used for multiple networks, then access control precision is maintained, but configuration time and setup complexity increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The firewall implements a universal configuration framework where access rules can be defined once and automatically apply to multiple network combinations. The system can identify traffic patterns and apply appropriate pre-configured rules or templates, maintaining precise access control while significantly reducing configuration time compared to manually configuring each firewall separately for each network pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The firewall utilizes configurable parameters and rules that can be dynamically adjusted based on traffic sources and destinations. By changing parameters such as source network, destination network, and access permissions in a centralized configuration, the system maintains precise access control for multiple networks without requiring separate configuration processes for each network combination.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3644570B1Firewall for building networks, a corresponding system and method and computer readable medium
Publication Date: 2021.07.28 ISE INDIVIDUELLE SOFTWARE & ELEKTRONIK GMBH
  • EP3644570B1 patent drawingFigure 1
  • EP3644570B1 patent drawingFigure 2
  • EP3644570B1 patent drawingFigure 3

AI summary

The invention relates to a firewall (210) connected to at least two local networks (101, 102) and a node (180) outside the local networks (101, 102) and configured to allow or deny access from one of the local networks (101, 102) or from the node (180) to one of the local networks (101, 102) or to the firewall (210) based on an access protocol, an access source address, and/or an access destination address. A corresponding system, a corresponding method, and a computer-readable medium are further described.