Compliance-Based Network Traffic Filtering for Brownfield Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems struggle to effectively filter network traffic based on the compliance status of communication endpoints, especially in 'brownfield systems' that lack support for context checks or have limited access to device compliance information.

Innovation Solution

A method for providing filter rules that depend on the compliance status of communication endpoints, allowing for the adjustment and application of filter rules based on the conformance status of nodes in a communication connection, thereby ensuring secure and compliant network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If compliance status checking is implemented in brownfield systems, then network security is improved, but system complexity increases due to lack of native support for context checks

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between brownfield systems lacking native compliance checking capabilities and the required security policies. This intermediary translates compliance requirements into filter rules that can be enforced without modifying the underlying brownfield system architecture, thereby improving security while managing complexity through layering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The compliance checking functionality is segmented into separate, manageable components including policy definition modules, compliance status determination modules, and filter rule generation modules. This segmentation allows the complex compliance checking task to be distributed across independent components that can be implemented and maintained separately in brownfield environments.

Inventive Principle:
Principle #1Segmentation

2Reliability

If filter rules are continuously updated based on compliance status, then network traffic filtering effectiveness is improved, but processing time increases

Engineering Contradiction:
Improvefiltering effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining compliance policies and pre-generating filter rules based on anticipated compliance states. When compliance status changes are detected, only the specific filter rules affected by the change are updated rather than reprocessing all rules, significantly reducing processing time while maintaining filtering effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The compliance status checking and filter rule updating is implemented as a periodic process rather than continuous real-time monitoring. Filter rules are updated at scheduled intervals or triggered by specific events, balancing the need for current filtering effectiveness with the constraint of processing time and system resource availability.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP4564738A1Filtering network traffic based on a compliance status of a communication endpoint
Publication Date: 2025.06.04 SIEMENS AG
  • EP4564738A1 patent drawingFigure 1
  • EP4564738A1 patent drawingFigure 2
  • EP4564738A1 patent drawingFigure 3

AI summary

The invention relates to a method for providing at least one filter rule (aFR) for filtering network traffic between at least one first node (1) and at least one second node (2) of a communication connection, comprising the steps of: - using (S2) at least one conformity status of the first node (1) and/or the second node (2), - defining (S3) the at least one filter rule (aFR) based on the at least one conformity status, wherein the defining (S3) of the at least one filter rule (aFR) comprises: o adapting (S3a) at least one existing filter rule (FR), and - providing (S4) the at least one filter rule (aFR). The invention also relates to a computer program product, a component and a higher-level system.