Communication Device Whitelist Segmentation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures, such as whitelisting, face challenges in implementing route redundancy protocols like ring and spanning tree protocols, as they require duplicating whitelist entries across all interfaces, leading to increased memory consumption and setup efforts, especially with multiple route switching patterns.

Innovation Solution

A communication device with distinct reception units for redundant and edge ports, where the redundant port is excluded from whitelist generation and control, and the edge port is included, allowing for efficient whitelist generation and storage based on received communication data, enabling secure and reliable network operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If whitelist entries are duplicated across all interfaces for route redundancy, then network security is maintained during route switching, but memory consumption and setup efforts increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmemory consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the network interfaces into two distinct types: redundant ports (excluded from whitelist generation) and edge ports (included in whitelist generation). This segmentation allows the system to apply different whitelist management policies to different interface types, thereby reducing overall memory consumption while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the whitelist generation behavior port-specific rather than system-wide. Edge ports receive whitelist protection while redundant ports do not, allowing security measures to be localized to where they are most needed (at network boundaries) rather than applied uniformly across all interfaces.

Inventive Principle:
Principle #3Local quality

2Reliability

If whitelist entries are duplicated across all interfaces for route redundancy, then network security is maintained during route switching, but setup efforts and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsetup efforts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting interfaces into redundant and edge ports with different whitelist policies, the system reduces setup complexity. Administrators only need to configure whitelists for edge ports, while redundant ports are automatically excluded, simplifying the overall configuration process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local quality principle reduces setup efforts by applying whitelist generation selectively only to edge ports rather than all ports. This localized approach means administrators don't need to manually duplicate whitelist entries across multiple redundant ports, significantly reducing configuration time and complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If all route switching patterns are simulated to generate whitelist, then comprehensive security coverage is achieved, but time and effort for generation increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidwhitelist generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts redundant ports from the whitelist generation process entirely. Since redundant ports are excluded from whitelist generation, there is no need to simulate all possible route switching patterns to populate whitelists for these ports, significantly reducing the time and computational effort required for whitelist generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary classification of ports into redundant and edge categories during setup. This preliminary action allows the system to avoid unnecessary whitelist generation for redundant ports in advance, saving time that would otherwise be spent simulating route switching patterns for ports that don't require whitelist protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10680893B2Communication device, system, and method
Publication Date: 2020.06.09 ALAXALA NETWORKS
  • US10680893B2 patent drawing
  • US10680893B2 patent drawing
  • US10680893B2 patent drawing

AI summary

It is an object of the present invention to achieve improvement of security by a whitelist function and improvement of network reliability by a network redundancy function at the same time. A packet relay device 100 includes packet reception units 200, a packet transfer unit 300, a S/W control unit 400, packet transmission units 500, and an input/output interface 600 and automatically generates a whitelist including an allowed communication rule. It is possible to select whether to perform communication control using the whitelist or to carry out data communication without using the whitelist for each data reception unit 200 that receives data.