Communication Device Whitelist Segmentation for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures, such as whitelisting, face challenges in implementing route redundancy protocols like ring and spanning tree protocols, as they require duplicating whitelist entries across all interfaces, leading to increased memory consumption and setup efforts, especially with multiple route switching patterns.
Innovation Solution
A communication device with distinct reception units for redundant and edge ports, where the redundant port is excluded from whitelist generation and control, and the edge port is included, allowing for efficient whitelist generation and storage based on received communication data, enabling secure and reliable network operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If whitelist entries are duplicated across all interfaces for route redundancy, then network security is maintained during route switching, but memory consumption and setup efforts increase
Solution Approach 1:
The patent segments the network interfaces into two distinct types: redundant ports (excluded from whitelist generation) and edge ports (included in whitelist generation). This segmentation allows the system to apply different whitelist management policies to different interface types, thereby reducing overall memory consumption while maintaining security where needed.
Solution Approach 2:
The patent applies local quality by making the whitelist generation behavior port-specific rather than system-wide. Edge ports receive whitelist protection while redundant ports do not, allowing security measures to be localized to where they are most needed (at network boundaries) rather than applied uniformly across all interfaces.
2Reliability
If whitelist entries are duplicated across all interfaces for route redundancy, then network security is maintained during route switching, but setup efforts and complexity increase
Solution Approach 1:
By segmenting interfaces into redundant and edge ports with different whitelist policies, the system reduces setup complexity. Administrators only need to configure whitelists for edge ports, while redundant ports are automatically excluded, simplifying the overall configuration process.
Solution Approach 2:
The local quality principle reduces setup efforts by applying whitelist generation selectively only to edge ports rather than all ports. This localized approach means administrators don't need to manually duplicate whitelist entries across multiple redundant ports, significantly reducing configuration time and complexity.
3Reliability
If all route switching patterns are simulated to generate whitelist, then comprehensive security coverage is achieved, but time and effort for generation increase
Solution Approach 1:
The patent extracts redundant ports from the whitelist generation process entirely. Since redundant ports are excluded from whitelist generation, there is no need to simulate all possible route switching patterns to populate whitelists for these ports, significantly reducing the time and computational effort required for whitelist generation.
Solution Approach 2:
The system performs preliminary classification of ports into redundant and edge categories during setup. This preliminary action allows the system to avoid unnecessary whitelist generation for redundant ports in advance, saving time that would otherwise be spent simulating route switching patterns for ports that don't require whitelist protection.
Data Source
AI summary
It is an object of the present invention to achieve improvement of security by a whitelist function and improvement of network reliability by a network redundancy function at the same time. A packet relay device 100 includes packet reception units 200, a packet transfer unit 300, a S/W control unit 400, packet transmission units 500, and an input/output interface 600 and automatically generates a whitelist including an allowed communication rule. It is possible to select whether to perform communication control using the whitelist or to carry out data communication without using the whitelist for each data reception unit 200 that receives data.


