Cloud Firewall Policy Management via Encapsulated Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firewall systems in enterprise networks face challenges when managing security policies for cloud computing environments, particularly in onboarding new assets and handling URL changes, leading to cumbersome processes and increased burden on gateways.

Innovation Solution

A cloud-based platform that routes IP data packets through a virtual cloud-based firewall, using a VPN connection to encapsulate and decapsulate packets, and manages firewall policies centrally, reducing the need for manual configuration and distributing traffic load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall systems are used to manage security policies for each enterprise application, then security control is maintained, but the complexity of policy management increases and onboarding new assets becomes technically challenging

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based policy management service as an intermediary between enterprise applications and the firewall system. This service automatically generates, updates, and manages security policies in the cloud, eliminating the need for manual firewall configuration for each application. The intermediary handles policy complexity centrally while maintaining security control, resolving the contradiction between reliable security and manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the cloud-based service to automatically provision security policies when new assets are onboarded. The system self-configures firewall rules based on asset information without requiring manual intervention from network administrators, thereby maintaining security control while reducing management complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If security policies are re-programmed for each new enterprise application, then access control is maintained, but the time and effort required for onboarding new assets increases

Engineering Contradiction:
Improveaccess controlVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cloud-based service performs preliminary actions by pre-generating security policies and configuring access control rules before assets need to connect to the enterprise network. When new assets are onboarded, their security policies are already prepared in the cloud, eliminating the time-consuming process of manual policy creation and enabling immediate secure access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically provisions security policies for new assets through self-service mechanisms. When an asset is registered, the cloud-based service automatically creates the necessary firewall rules and access control configurations without requiring manual re-programming, thus maintaining access control while dramatically reducing onboarding time.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the firewall maintains security policies per vendor basis, then security granularity is improved, but the burden on gateways to handle traffic increases

Engineering Contradiction:
Improvesecurity granularityVSAvoidgateway operation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the complex policy management function from the gateway device and relocates it to a cloud-based service. The gateway's role is simplified to merely forwarding traffic, while the cloud service handles vendor-specific security policies and granular access control. This extraction maintains security granularity while significantly reducing the operational burden on gateways.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based service acts as an intermediary that handles vendor-specific security policies and traffic management. Instead of gateways directly managing complex per-vendor policies, the cloud intermediary processes these requirements centrally, maintaining security granularity while easing gateway operations by removing complex policy enforcement from the gateway device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12192176B2Cloud based platform to efficiently manage firewall rules and data traffic
Publication Date: 2025.01.07 HONEYWELL INTERNATIONAL INC
  • US12192176B2 patent drawing
  • US12192176B2 patent drawing
  • US12192176B2 patent drawing

AI summary

Various embodiments described herein relate to a virtual network with a cloud-based server, cloud-based firewall and a cloud-based service. The cloud-based server is in communication with a client installed on a gateway to receive an encapsulated IP data packet from one or more applications installed on the gateway. The cloud-based configured to decapsulate the encapsulated IP data packet verify a security certificate based on a first information and configure a cloud-based firewall based on a second information. The cloud-based server is configured to route the one or more IP data packets to the cloud-based firewall for processing each IP data packet based on the second information. In response to the one or more IP data packets being compliant with the first information provided to authenticate the gateway and the second information provided to configure the cloud-based firewall, routing the one or more IP data packets to the cloud-based service.