Centralized Firewall Service Platform for Managed Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for deploying and managing managed firewall services via Customer Premises Equipment (CPE) are costly, complex, and inefficient, requiring extensive on-site installations and maintenance, which increases operational costs and reduces service provider margins.

Innovation Solution

A network-based managed firewall service model using an IP Service Delivery Platform that centralizes firewall and VPN functionality within the service provider's network, eliminating the need for CPE devices at each customer site and enabling remote provisioning and management through a scalable and intelligent IP Service Processing Switch and Service Management System.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If CPE devices are deployed at each customer site for managed firewall services, then service coverage and customer control are improved, but operational costs and device complexity increase

Engineering Contradiction:
Improveservice coverageVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the firewall service functionality from customer-premises CPE devices and relocates it to the service provider's network infrastructure. Specifically, the firewall processing is moved to border routers or dedicated security appliances at the service provider's network edge, eliminating the need for complex CPE devices at each customer site while maintaining comprehensive service coverage through centralized management.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If manual provisioning processes are used for CPE installation and configuration, then service customization is improved, but productivity and time-to-market deteriorate

Engineering Contradiction:
Improveservice customizationVSAvoidproductivity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring firewall policies, security rules, and service parameters in the service provider's centralized management system before service deployment. The system automatically provisions these pre-configured services to multiple customer sites simultaneously, eliminating the need for manual on-site configuration while maintaining service customization capabilities through template-based deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating virtual instances of firewall service configurations from master templates. The centralized management system replicates security policies and firewall rules across multiple network elements and customer sites, enabling rapid service deployment without manual intervention at each location while preserving service customization through template modification.

Inventive Principle:
Principle #26Copying

3Reliability

If on-site installation and troubleshooting are performed for CPE devices, then service reliability is improved, but operational costs and loss of time increase

Engineering Contradiction:
Improveservice reliabilityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the centralized management system to automatically monitor, diagnose, and resolve firewall service issues without requiring on-site technician intervention. The system includes automated logging, remote configuration capabilities, and self-healing mechanisms that maintain service reliability while eliminating the time loss associated with physical travel and on-site troubleshooting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary in the form of a centralized network operations center (NOC) and automated management system that mediates between service failures and resolution. This intermediary provides remote monitoring and diagnostics, allowing technicians to troubleshoot and resolve issues from a central location without traveling to customer sites, thereby maintaining reliability while reducing time loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If traditional CPE-based managed firewall services are deployed, then network security control is improved, but operational costs and device complexity increase

Engineering Contradiction:
Improvenetwork security controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple distributed CPE firewall devices into a single centralized firewall service platform at the service provider's network. This consolidation maintains network security control through unified policy management and centralized monitoring while dramatically reducing device complexity by eliminating redundant firewall hardware and software at each customer premises, replacing them with simpler edge routers or access devices.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8250357B2Tunnel interface for securing traffic over a network
Publication Date: 2012.08.21 ATHENA SECURITY LLP
  • US8250357B2 patent drawing
  • US8250357B2 patent drawing
  • US8250357B2 patent drawing

AI summary

A flexible, scalable hardware and software platform that allows a service provider to easily provide internet services, virtual private network services, firewall services, etc., to a plurality of customers. One aspect provides a method and system for delivering security services. This includes connecting a plurality of processors in a ring configuration within a first processing system, establishing a secure connection between the processors in the ring configuration across an internet protocol (IP) connection to a second processing system to form a tunnel, and providing both router services and host services for a customer using the plurality of processors in the ring configuration and using the second processing system. A secure communications tunnel is formed by routing all packets for the tunnel through an encrypting router at the sending end to obtain encrypted packets, and routing the encrypted packets through a decrypting router at the receiving end of an IP connection.