Dynamic Firewall Policy Management via PEP and PDP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewalls are inflexible and ineffective in public networks, as they often require users to initiate connections through specific application proxies, restrict access to specific applications, and do not adequately manage trust between users and network components, leading to unsatisfactory user experiences and security vulnerabilities.

Innovation Solution

The implementation of a policy enforcement point (PEP) and policy decision point (PDP) system that allows nodes to send their preferences or options to manage firewall configurations dynamically, enabling flexible communication and improved network protection by authenticating and authorizing requests using protocols like FCON, which allows for secure and adaptable firewall management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall configurations are used, then network security is maintained, but user flexibility and adaptability are reduced

Engineering Contradiction:
Improvefirewall configuration flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The firewall system transitions from static administrator-configured rules to dynamic user-requested policies. The PEP and PDP enable real-time modification of firewall configurations based on user needs, allowing the system to adapt dynamically while maintaining security through authenticated policy requests.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Users can directly request and obtain their own firewall policy configurations without administrator intervention. The system enables users to self-serve by submitting policy requests through the FCON protocol and receiving automated approvals or rejections based on pre-configured security rules.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If firewall rules restrict access to specific applications, then network security is improved, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improveuser convenienceVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback loop where users request policy changes, the PDP evaluates requests against security rules, and automatic decisions are communicated back to users. This automated feedback mechanism maintains security controls while improving user convenience by eliminating manual administrator intervention for routine requests.

Inventive Principle:
Principle #23Feedback

3Device complexity

If firewall configurations are set by administrators, then centralized control is maintained, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvefirewall management complexityVSAvoidautomatic policy management
Core Design Contradiction:
Device complexityVSExtent of automation

Solution Approach 1:

The firewall management system is segmented into distinct functional components: PEP for policy enforcement, PDP for policy decisions, and separate authentication mechanisms. This segmentation distributes complexity across multiple specialized modules, making the overall system more manageable and easier to automate while maintaining centralized security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8955088B2Firewall control for public access networks
Publication Date: 2015.02.10 FUTUREWEI TECHNOLOGIES INC
  • US8955088B2 patent drawing
  • US8955088B2 patent drawing
  • US8955088B2 patent drawing

AI summary

An apparatus comprising a policy enforcement point (PEP) configured to enforce firewall policies in a network, and a policy decision point (PDP) coupled to the PEP and configured to manage the PEP based on at least one firewall policy option received from at least one node. Also disclosed is a network component comprising at least one processor configured to implement a method comprising receiving a request from a node regarding a firewall policy entry, authenticating the node, processing the request to manage a firewall using a firewall control protocol, and sending a reply to the node regarding processing the request. Also disclosed is a method comprising signaling a PDP to establish a session associated with a source address and a requested protocol, and receiving an indication when the session is allowed.