Building Network Firewall for Multi-Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access control between multiple networks in a building setting is complex, especially when these networks can be accessed from outside, as existing solutions require multiple firewalls and extensive configuration, leading to inefficiencies and increased complexity.
Innovation Solution
A firewall system that connects to at least two local area networks and an external node, allowing three-way control of data traffic by establishing tunnels between networks using protocols like HTTPS/Websocket or VPN, and applying rules to allow or deny access based on source and destination addresses and protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple firewalls are deployed to control access between multiple networks, then access control security is improved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent combines multiple firewall functions into a single firewall device that can handle access control between multiple networks simultaneously. The firewall is configured with multiple network interfaces connected to different networks and can apply access rules to traffic between any combination of these networks, eliminating the need for separate firewalls for each network pair.
Solution Approach 2:
The firewall is designed with multi-functional capabilities to perform access control for multiple network combinations through a single device. It can identify traffic sources and destinations across different networks and apply appropriate access rules dynamically, making one firewall universal for managing access between multiple networks rather than requiring dedicated firewalls for each network pair.
2Adaptability or versatility
If multiple firewalls are used to control access between multiple networks, then access control coverage is improved, but the number of physical ports and hardware resources increase
Solution Approach 1:
The patent merges the functionality of multiple firewalls into a single device with multiple network interfaces. Each interface connects to a different network, and the single firewall device can manage access control for all network combinations, reducing the total number of physical devices and ports required compared to deploying separate firewalls for each network pair.
Solution Approach 2:
The firewall device is designed with universal access control capabilities that allow it to monitor and control traffic between any combination of connected networks through its multiple interfaces. This multi-functional design enables one device to provide the access control coverage that would otherwise require multiple dedicated firewalls, thereby reducing hardware resource requirements.
3Manufacturing precision
If traditional firewall configurations are used for multiple networks, then access control precision is maintained, but configuration time and setup complexity increase
Solution Approach 1:
The firewall implements a universal configuration framework where access rules can be defined once and automatically apply to multiple network combinations. The system can identify traffic patterns and apply appropriate pre-configured rules or templates, maintaining precise access control while significantly reducing configuration time compared to manually configuring each firewall separately for each network pair.
Solution Approach 2:
The firewall utilizes configurable parameters and rules that can be dynamically adjusted based on traffic sources and destinations. By changing parameters such as source network, destination network, and access permissions in a centralized configuration, the system maintains precise access control for multiple networks without requiring separate configuration processes for each network combination.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a firewall (210) connected to at least two local networks (101, 102) and a node (180) outside the local networks (101, 102) and configured to allow or deny access from one of the local networks (101, 102) or from the node (180) to one of the local networks (101, 102) or to the firewall (210) based on an access protocol, an access source address, and/or an access destination address. A corresponding system, a corresponding method, and a computer-readable medium are further described.