Dynamic Firewall Access Control via Conditional Grantor Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems lack the ability to automatically and dynamically identify and authenticate remote network devices, leading to vulnerabilities such as unauthorized access, DDoS attacks, and man-in-the-middle attacks, as they cannot coordinate with headend firewalls to allow specific and secure connections.

Innovation Solution

A system with a conditional access grantor module at the central network device determines remote network parameters and dynamically configures firewalls to permit only authorized access by using unique identifiers and connection details, ensuring secure communication between remote and central network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a headend firewall is exposed to the network to allow access, then network accessibility is improved, but security against unauthorized access and attacks deteriorates

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidunauthorized access and attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The firewall rule set is dynamically updated based on authenticated device parameters. The system transitions from a static firewall configuration to a dynamic one where access rules are automatically generated and modified in real-time based on the requesting device's identity and parameters, allowing legitimate access while blocking unauthorized attempts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically identifies authenticated devices, extracts their network parameters, and configures firewall rules without manual intervention. The firewall service self-adjusts its configuration based on the authentication outcomes and device parameters, eliminating the need for administrators to manually manage access rules.

Inventive Principle:
Principle #25Self-service

2Productivity

If firewall rules are configured to allow broad access, then network connectivity is improved, but vulnerability to DDoS attacks and scanning deteriorates

Engineering Contradiction:
Improvenetwork connectivityVSAvoidDDoS attacks and scanning
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

Instead of applying uniform firewall rules to all traffic, the system creates highly specific local rules tailored to each authenticated device's parameters. Each device receives a customized set of firewall rules that precisely match its network characteristics, allowing legitimate traffic while blocking broad-based attack patterns.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes firewall parameters dynamically based on device authentication and network conditions. Firewall rules are generated with specific parameters (source IP, destination IP, ports, protocols) that match the authenticated device's characteristics, transforming the firewall from a static barrier to an adaptive security layer.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual firewall configuration is used to secure access, then security control is improved, but system complexity and administrative burden deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically performs device identification, parameter extraction, and firewall rule generation without administrator intervention. The security control process serves itself by automatically managing the entire workflow from authentication to firewall configuration, eliminating manual administrative tasks while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where firewall rule effectiveness is continuously monitored and adjusted based on authentication outcomes and network traffic patterns. The system learns from authentication results and automatically refines firewall configurations, improving security control while reducing administrative overhead through automated optimization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20220278960A1Systems and methods for dynamic access control for devices over communications networks
Publication Date: 2022.09.01 IP TECHNOLOGY LABS LLC
  • US20220278960A1 patent drawing
  • US20220278960A1 patent drawing
  • US20220278960A1 patent drawing

AI summary

The invention is that of systems and methods to reduce or eliminate network resource exposure to unauthorized network users. The methods described herein are designed to only permit authenticated remote network device access to central network services based on the content of requests from remote network devices seeking access. A system as described herein is configured with conditional access grantor and request modules located on central and remote networks, respectively. A conditional access grantor module dynamically configures a central network firewall or equivalent to permit or deny access from the specific devices on the remote network. A database is provided for storing of remote device details or parameters supplied by the grantor module and required for connection thereby to the central network. This prevents scanning, duplicate access, man-in-the-middle attacks, DDoS attacks, or access by unauthorized devices commonly taking place on IP networks such as the Internet as only the network parameters of an authorized remote will be able to communicate.