Dynamic Firewall Rule Updates via Signed Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network protection solutions provide limited dynamic access control, as firewall rules are determined during initial authentication and do not update in real-time, leading to restricted access control between rule refreshes.
Innovation Solution
A method and system that establish a network tunnel between a client device and a gateway with a firewall, allowing real-time updates of firewall rules using signed tokens, enabling dynamic access control by checking conditions before applying rules and sending actions to the client device if conditions are not met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firewall rules are determined during initial authentication, then access control is established, but dynamic access control between rule refreshes is limited
Solution Approach 1:
The patent implements dynamic firewall rule updates by receiving updated rules from the authentication server during the active tunnel session. The gateway dynamically modifies existing firewall rules without requiring tunnel re-establishment, enabling real-time access control adaptation to changing user needs or security policies.
Solution Approach 2:
The system establishes a feedback loop where the authentication server pushes updated firewall rules to the gateway during active sessions. This feedback mechanism allows continuous monitoring and adjustment of access control based on current user authentication status, time-based policies, or resource availability.
2Extent of automation
If the gateway implements both VPN server and firewall functions, then centralized access control is achieved, but device complexity increases
Solution Approach 1:
The patent combines VPN server and firewall functionality into a single gateway device. The gateway simultaneously handles tunnel establishment, authentication, and packet filtering operations, consolidating multiple security functions into one centralized system that manages access control automatically.
Solution Approach 2:
The gateway is designed as a multi-functional device that performs authentication, tunnel management, and firewall filtering operations. This universal design allows a single device to handle diverse security tasks without requiring separate specialized components for each function.
Data Source
AI summary
In one approach, a computer-implemented method includes: implementing, by a gateway, a firewall including firewall rules for selectively blocking and allowing network traffic between a client device and one or more network devices in a private network; receiving, by the gateway from the client device, a first access rule; and in response to receiving the first access rule, creating a first firewall rule of the firewall rules.


