Edge Firewall Agents for Wi-Fi Traffic Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls in data center architectures often become bottlenecks due to slower hardware and complex rule chains, leading to latency and workload imbalances, especially in local access networks where integration with other infrastructure is lacking.
Innovation Solution
Implementing centralized firewall rules at the edge of a data communication network, with a Wi-Fi controller distributing customized application control policies to access points for prioritizing network traffic and performing deep packet inspection, thereby reducing latency and workload on networking devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall is added to the data center architecture to control network traffic, then network security is improved, but network performance deteriorates due to bottlenecks and latency
Solution Approach 1:
The patent segments the firewall functionality by deploying distributed firewall agents at edge access points rather than a single centralized firewall. This distributes the filtering workload across multiple nodes, preventing bottlenecks while maintaining security policies through centralized management.
Solution Approach 2:
The patent moves firewall processing from the traditional centralized data center dimension to the edge network dimension. By implementing firewall agents at access points where network traffic enters, the system adds a spatial dimension to security enforcement, enabling early packet filtering before traffic reaches core network devices.
2Speed
If faster hardware is used in firewalls to reduce latency, then processing speed is improved, but additional latency remains due to buffering and packet filtering requirements
Solution Approach 1:
The patent implements preliminary action by performing firewall rule evaluation and packet filtering at the edge access points before traffic enters the core network. This early filtering prevents unnecessary traffic from traversing the entire network to reach centralized firewalls, reducing overall latency.
Solution Approach 2:
The patent extracts the packet filtering function from the main network traffic flow by implementing separate firewall agent processes at edge devices. This allows filtering operations to occur in parallel with normal network operations, minimizing impact on traffic throughput.
3Reliability
If a chain of rules and policies is applied at the firewall to ensure comprehensive security, then security coverage is improved, but device complexity increases causing bottlenecks
Solution Approach 1:
The patent segments the complex rule chain by distributing it across multiple firewall agents at different edge locations. Each agent handles a portion of the filtering workload locally, reducing the complexity burden on any single device while maintaining comprehensive security coverage through coordinated policy enforcement.
Solution Approach 2:
The patent introduces a centralized firewall management system as an intermediary that handles complex rule orchestration and policy distribution. This mediator manages the complexity of rule chains centrally while allowing distributed agents to execute simpler local filtering operations.
Data Source
AI summary
Application data collected by an IDS (intrusion detection system) on the data communication network and concerning applications executing on stations coupled to the plurality of access points, is received. Additionally, firewall rules for applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points, are received. The firewall rules can be parsed to expose configured actions for applications. A customized application control policy is prepared for each particular application for implementation on the network edge by at least one of the plurality of access points.


