Edge Firewall Agents for Wi-Fi Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in data center architectures often become bottlenecks due to slower hardware and complex rule chains, leading to latency and workload imbalances, especially in local access networks where integration with other infrastructure is lacking.

Innovation Solution

Implementing centralized firewall rules at the edge of a data communication network, with a Wi-Fi controller distributing customized application control policies to access points for prioritizing network traffic and performing deep packet inspection, thereby reducing latency and workload on networking devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is added to the data center architecture to control network traffic, then network security is improved, but network performance deteriorates due to bottlenecks and latency

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the firewall functionality by deploying distributed firewall agents at edge access points rather than a single centralized firewall. This distributes the filtering workload across multiple nodes, preventing bottlenecks while maintaining security policies through centralized management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent moves firewall processing from the traditional centralized data center dimension to the edge network dimension. By implementing firewall agents at access points where network traffic enters, the system adds a spatial dimension to security enforcement, enabling early packet filtering before traffic reaches core network devices.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Speed

If faster hardware is used in firewalls to reduce latency, then processing speed is improved, but additional latency remains due to buffering and packet filtering requirements

Engineering Contradiction:
Improvefirewall processing speedVSAvoidnetwork latency
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent implements preliminary action by performing firewall rule evaluation and packet filtering at the edge access points before traffic enters the core network. This early filtering prevents unnecessary traffic from traversing the entire network to reach centralized firewalls, reducing overall latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the packet filtering function from the main network traffic flow by implementing separate firewall agent processes at edge devices. This allows filtering operations to occur in parallel with normal network operations, minimizing impact on traffic throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a chain of rules and policies is applied at the firewall to ensure comprehensive security, then security coverage is improved, but device complexity increases causing bottlenecks

Engineering Contradiction:
Improvesecurity coverageVSAvoidfirewall complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex rule chain by distributing it across multiple firewall agents at different edge locations. Each agent handles a portion of the filtering workload locally, reducing the complexity burden on any single device while maintaining comprehensive security coverage through coordinated policy enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized firewall management system as an intermediary that handles complex rule orchestration and policy distribution. This mediator manages the complexity of rule chains centrally while allowing distributed agents to execute simpler local filtering operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12075249B2Controlling wi-fi traffic from network applications with centralized firewall rules implemented at the edge of a data communication network
Publication Date: 2024.08.27 FORTINET INC
  • US12075249B2 patent drawing
  • US12075249B2 patent drawing
  • US12075249B2 patent drawing

AI summary

Application data collected by an IDS (intrusion detection system) on the data communication network and concerning applications executing on stations coupled to the plurality of access points, is received. Additionally, firewall rules for applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points, are received. The firewall rules can be parsed to expose configured actions for applications. A customized application control policy is prepared for each particular application for implementation on the network edge by at least one of the plurality of access points.