Centralized Network Security via GRE Tunnel Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and maintaining premise-based firewalls for multiple business customers becomes burdensome as the number of customers increases, requiring a more efficient and scalable solution for network security services.

Innovation Solution

Implementing network-based security services that route data traffic through a generic routing encapsulation (GRE) tunnel from customer edge routers to Ethernet services routers, then to aggregation switches and security modules for filtering, before returning to provider edge routers, allowing for centralized management and virtualization of firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If premise-based firewalls are installed at each customer location, then network security is provided for each customer, but the complexity and burden of managing and maintaining multiple individual firewalls increases significantly as the number of customers grows

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual customer firewalls into a single centralized firewall appliance located at the service provider's facility. This consolidation provides network security for multiple customers through one unified device, eliminating the need to manage separate firewalls at each customer premises while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a service provider-managed firewall as an intermediary between the customer's network and the external network. This centralized firewall acts as a mediator that filters and secures traffic for multiple customers, replacing the need for individual customer-side firewalls and simplifying management through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual firewalls are installed and maintained at each customer premise, then security services are provided, but the time and resources required for installation, monitoring, and updating increase unduly as customer numbers increase

Engineering Contradiction:
Improvesecurity service provisionVSAvoidtime for installation and maintenance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized firewall system enables self-service capabilities where the service provider can remotely manage, monitor, and update security services for all customers through a single interface. This eliminates the need for technicians to physically visit each customer location for firewall maintenance, significantly reducing the time and resources required for installation and updates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By consolidating firewall management into a single centralized system, the patent combines multiple maintenance tasks into one unified operation. The service provider can update security policies, monitor threats, and manage configurations for all customers simultaneously, reducing the cumulative time required compared to managing individual firewalls separately.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate premise-based firewalls are deployed for each customer, then customized security services can be provided, but the cost and complexity of deployment and management increases

Engineering Contradiction:
Improvecustomizable security servicesVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized firewall appliance provides universal functionality by serving multiple customers through a single device. The system can be configured to provide customized security services for each customer while maintaining a unified infrastructure, allowing the same hardware platform to deliver tailored security policies and rules for different customer requirements without requiring separate physical firewalls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8549610B2Network-based security services for managed internet service
Publication Date: 2013.10.01 AT&T INTELLECTUAL PROPERTY I L P
  • US8549610B2 patent drawing
  • US8549610B2 patent drawing
  • US8549610B2 patent drawing

AI summary

Data traffic is routed from a customer edge (CE) router to an Ethernet services router via a generic routing encapsulation (GRE) tunnel. Upon routing the data traffic from the CE router to the Ethernet services router, the data traffic is routed from the Ethernet services router to an aggregation switch. Upon routing the data traffic from the Ethernet services router to the aggregation switch, the data traffic is routed from the aggregation switch to a service switch through a security module, the security module configured to filter the data traffic. The filtered data traffic is routed from the service switch to the Ethernet services router. Upon routing the filtered data traffic from the service switch to the Ethernet services router, the filtered data traffic is routed from the Ethernet services router to a provider edge (PE) router.