Containerized Firewall for Embedded Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating advanced next-generation firewall features into embedded networking devices is challenging due to incompatible toolchains and conflicting libraries, making it difficult to provide robust firewall protection.

Innovation Solution

Implementing containerization in embedded networking devices by spawning a new container with a separate toolchain and custom runtime libraries, allowing the firewall to operate independently from the host OS with different user privileges, and utilizing custom libraries for enhanced security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a software development kit (SDK) is used to provide next generation firewall features in embedded networking devices, then advanced firewall functionalities are added, but incompatible toolchains and conflicting supporting libraries cause compromise containment and integration difficulties

Engineering Contradiction:
Improvefirewall functionalityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the firewall software into isolated container environments, each with its own dedicated toolchain and runtime libraries. This segmentation prevents conflicts between different firewall components and the host system, allowing multiple Next-Generation Firewall (NGFW) features to coexist without integration issues while maintaining the embedded device's stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces containerization technology as an intermediary layer between the host operating system and the firewall software components. This intermediary provides standardized interfaces and isolation mechanisms, enabling seamless integration of diverse firewall functionalities without direct conflicts between toolchains or libraries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep packet inspection and analysis features are integrated into embedded firewalls, then security inspection capability is enhanced, but system resource consumption increases

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The containerized architecture enables selective deployment of deep packet inspection capabilities only where needed, rather than requiring the entire embedded system to support all inspection features simultaneously. This allows the system to allocate computational resources efficiently, providing enhanced security inspection capability for specific traffic flows while maintaining lower overall resource consumption for routine operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12199951B2Containerized firewall in an embedded device for protecting against malicious data traffic on a data communication network
Publication Date: 2025.01.14 FORTINET INC
  • US12199951B2 patent drawing
  • US12199951B2 patent drawing
  • US12199951B2 patent drawing

AI summary

A new container of a pool of containers is spawned in the operating system of the embedded networking device to execute a firewall separate from an operating system of a host device. Each of the containers is generated by a separate toolchain to include custom runtime libraries. The firewall utilizes the custom libraries rather than the host libraries, and wherein user privileges within a container is different from user privileges for the host. The new container executes a firewall instance to inspect data packets processed by the embedded networking device.