Distributed Cloud Firewall Segmentation for Low-Latency Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current FWaaS technologies suffer from decreased network performance, increased latency, and limited flexibility in customizing security rules and policies to meet organizational needs, leading to potential vulnerabilities and security breaches.

Innovation Solution

Implementing a cloud-based firewall system with distributed firewalls and user-specific, segmented firewall rules that allow for granular access control, enabling seamless integration with features like Deep Packet Inspection and DNS Filtering, and allowing administrators to manage rules through a GUI interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized FWaaS is used, then security management is simplified, but network performance decreases and latency increases

Engineering Contradiction:
Improvesecurity managementVSAvoidnetwork performance
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent segments the centralized firewall service into distributed firewall components deployed across multiple edge locations and network nodes. Each segment handles local traffic filtering independently, eliminating the performance bottleneck of centralized processing while maintaining simplified security policy management through a centralized configuration interface that pushes rules to all segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional centralized architecture to a multi-dimensional distributed architecture by deploying firewall instances across geographic locations, network layers, and device types. This dimensional expansion allows traffic to be filtered closer to the source, reducing latency while maintaining centralized control planes for policy management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If standardized firewall rules are used, then deployment is simplified, but flexibility to meet organizational needs is limited

Engineering Contradiction:
ImprovedeploymentVSAvoidcustomization flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic firewall rules that can be automatically adjusted based on real-time threat intelligence, user behavior analysis, and contextual factors. The system transitions from static pre-configured rules to dynamic policies that adapt to changing organizational needs and threat landscapes, with centralized management providing the flexibility to customize rules without manual deployment at each node.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables parameter-based rule customization where security policies are defined by adjustable parameters (e.g., threat levels, user roles, time of day, device types) rather than fixed rules. This allows organizations to customize security behavior by changing parameters centrally, achieving both easy deployment through parameter templates and high flexibility through parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traffic is routed through centralized security infrastructure, then security coverage is comprehensive, but latency increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary security actions by pre-processing and filtering traffic at distributed edge locations before it reaches the centralized infrastructure. Common security operations (e.g., known good/bad traffic filtering, basic packet inspection) are performed in advance at the network edge, reducing the volume of traffic requiring centralized processing and minimizing latency while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary distributed firewall nodes that act as mediators between end devices and the centralized security infrastructure. These intermediaries handle local traffic filtering and only forward suspicious or complex traffic to the centralized system, reducing the latency burden on comprehensive security coverage while maintaining security effectiveness through layered inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12563017B2Identity-based distributed cloud firewall for access and network segmentation
Publication Date: 2026.02.24 720 IT UAB
  • US12563017B2 patent drawing
  • US12563017B2 patent drawing
  • US12563017B2 patent drawing

AI summary

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.