Dynamic Firewall Rule Generation for Remote Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure remote access solutions for enterprise networks lack granular profile-based access control, relying on cumbersome static firewall rules and failing to account for device mobility and application access provisioning across regions, leading to inefficient resource access management.

Innovation Solution

Implementing a method that processes remote-device data messages based on data-message attributes from a remote device management system, using source network address translation, firewall operations, and network micro-segmentation to enforce policies and restrict access, ensuring that remote devices access only segregated resources based on their geographic location and user identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static firewall rules are used for access control, then security policies can be enforced, but the system becomes cumbersome to provision and manage due to rule bloat from the huge number of profiles

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidfirewall rule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote device management system as an intermediary that generates dynamic firewall rules based on device profiles, user identities, and application requirements. This mediator translates complex access control requirements into automated rule generation, eliminating the need for manual firewall rule management while maintaining security policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions from static firewall rules to dynamic rule generation based on real-time device attributes, user profiles, and application contexts. The firewall rules are automatically adapted to changing conditions such as device mobility across regions and application access provisioning, eliminating rule bloat while maintaining comprehensive security coverage.

Inventive Principle:
Principle #15Dynamics

2Reliability

If static firewall rules are used for access control, then security can be maintained, but the system fails to account for device mobility across regions and application access provisioning

Engineering Contradiction:
Improvesecurity maintenanceVSAvoiddevice mobility and application access adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system employs dynamic firewall rule generation that automatically adapts to device mobility across different geographic regions and application access requirements. The rules are continuously updated based on real-time device profiles, user identities, and application contexts, enabling the system to maintain security while accommodating changing access patterns and regional restrictions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of firewall rules from static configurations to dynamic parameters derived from device attributes, user profiles, and application requirements. This allows the system to automatically adjust access control policies based on varying conditions such as geographic location, device type, and application-specific needs, thereby achieving both security maintenance and adaptability.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If granular profile-based access control is implemented, then access management efficiency improves, but the system complexity increases due to the need for real-time attribute processing

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidreal-time attribute processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-generating and caching firewall rules based on device profiles and user identities before actual access requests occur. The remote device management system prepares access control policies in advance, allowing rapid rule application when devices attempt to access resources, thereby improving efficiency while managing complexity through pre-computation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a remote device management system as an intermediary that handles the complexity of real-time attribute processing. This mediator collects device attributes, user profiles, and application requirements, then translates them into optimized firewall rules, shielding the core network infrastructure from complexity while enabling efficient granular access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3599742B1Distributing remote device management attributes to service nodes for service rule processing
Publication Date: 2022.08.03 NICIRA INC
  • EP3599742B1 patent drawingFigure 1
  • EP3599742B1 patent drawingFigure 2
  • EP3599742B1 patent drawingFigure 3~5

AI summary

Some embodiments provide novel methods for processing remote-device data messages in a network based on data-message attributes from a remote device management (RDM) system. For instance, the method of some embodiments identifies a set of RDM attributes associated with a data message, and then performs one or more service operations based on identified RDM attribute set.