Centralized Star Network Architecture for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security is challenging, particularly in extending private networks over insecure networks like the Internet, as existing VPN solutions often require complex firewall rule coordination across geographically distant sites and lack centralized control over access rights, leading to potential security breaches and connection difficulties.

Innovation Solution

A star-connected network architecture where a central server node establishes encrypted connections with client nodes using SSL sessions, routing all communications through a firewall with dynamically updated rules based on a security policy, ensuring centralized control and authentication via tamper-resistant hardware modules, and employing a security policy engine to manage access rights and detect potential attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed private networks use leased lines to couple geographically distant local area networks, then network connectivity is established, but cost increases and firewall rule coordination becomes complex

Engineering Contradiction:
Improvenetwork connectivityVSAvoidfirewall rule coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central server as an intermediary node that mediates all communications between client nodes. This central server consolidates firewall rule management and security policy enforcement, eliminating the need for complex coordinated firewall rules at each distributed site. The central server acts as a trusted intermediary that simplifies the network architecture while maintaining reliable connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote users negotiate the firewall to access the private network, then access is granted, but centralized control over access rights is lost

Engineering Contradiction:
Improveaccess to private networkVSAvoidcentralized control
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges firewall functionality and security policy enforcement into a single centralized server. This consolidation maintains centralized control over access rights while simplifying the access mechanism for remote users. Instead of managing distributed firewall rules across multiple nodes, all security decisions are made centrally by the server that mediates communications.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If firewall rules are coordinated at each site based on local requirements, then local access needs are met, but connection difficulties arise and security policies diverge

Engineering Contradiction:
Improvelocal access requirementsVSAvoidconnection stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network into client nodes and a central server, with all communications routed through the server. This segmentation allows each client to have simple, consistent connection rules while the central server handles complex security policies. Local access requirements are met through the server's ability to enforce differentiated security policies for different clients without requiring complex local firewall configurations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8544081B2Secure network architecture
Publication Date: 2013.09.24 BRITISH TELECOM PLC
  • US8544081B2 patent drawing
  • US8544081B2 patent drawing
  • US8544081B2 patent drawing

AI summary

The present invention provides a star-connected network (C1-C4, P1-P8) having a number of peripheral nodes (P1-P8) and a central control arrangement (C1-C4). Each peripheral node has means for restricting communications across the network to the central control arrangement using a respective encrypted connection unless the peripheral node has received explicit authorisation from the control arrangement to set up a direct connection with another peripheral node. The central control arrangement comprises: means for establishing an encrypted connection with each peripheral node; means for exchanging control packets with two or more peripheral nodes using two or more respective encrypted connections in order to set up an authorised connection between two peripheral nodes; a database storing security policy information specifying what connections between peripheral nodes are allowable; and authorisation means for authorising connections which are allowable according to the stored security policy information using the control packet exchanging means.