Firewall Access Control Using BGP Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall policies are inefficient for larger scale security policies, particularly at autonomous system boundaries, as they require significant administrative overhead to maintain dynamic IP protocol-level security rules, which are not effectively managed by existing methods.

Innovation Solution

Implementing firewall access control using Border Gateway Protocol (BGP) attributes, where packets are routed and firewall policies are applied based on BGP attributes associated with IP addresses, reducing administrative burdens and enhancing policy definition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall policies are implemented by manually specifying external IP address blocks, then access control can be applied, but significant administrative overhead is required to maintain dynamic IP protocol-level security rules

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces BGP attributes as an intermediary layer between routing decisions and firewall policy enforcement. Instead of directly managing IP address blocks, the system uses BGP community attributes and AS path attributes to represent groups of IP addresses, allowing firewall rules to reference these attributes rather than individual IP ranges. This intermediary representation reduces administrative overhead while maintaining security effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the firewall device multi-functional by combining routing functionality (BGP speaker) with firewall policy enforcement in a single device. The firewall can simultaneously perform routing decisions based on BGP attributes and apply security policies based on the same attributes, eliminating the need for separate manual IP address block management and reducing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If firewall policies are applied at IP protocol level for each individual IP address, then precise security control is achieved, but the complexity of managing dynamic IP ranges increases significantly

Engineering Contradiction:
Improvesecurity rule precisionVSAvoidpolicy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the large set of IP addresses into groups represented by BGP attributes (community attributes and AS path attributes). Instead of managing individual IP address rules, the system creates firewall policies that reference these attribute-based segments. This segmentation maintains precision in security control while dramatically reducing the number of rules needed to manage dynamic IP ranges.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter basis for firewall rules from specific IP address values to BGP attribute parameters (community strings and AS path sequences). This parameter transformation allows the firewall to maintain precise control over security decisions while adapting automatically to routing changes without requiring manual updates to IP address blocks, thereby reducing policy management complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8931073B2Firewall access control with border gateway protocol attributes
Publication Date: 2015.01.06 TIME WARNER CABLE ENTERPRISES LLC
  • US8931073B2 patent drawing
  • US8931073B2 patent drawing
  • US8931073B2 patent drawing

AI summary

Packets are routed from at least one internet protocol (IP) address in accordance with border gateway protocol (BGP); while carrying out the routing in accordance with the border gateway protocol (BGP), at least one border gateway protocol (BGP) attribute associated with the at least one internet protocol (IP) address is noted. A firewall policy is applied to the packets from the at least one internet protocol (IP) address based on the at least one border gateway protocol (BGP) attribute associated with the at least one internet protocol (IP) address. Techniques may be implemented, for example, on a router or on a separate firewall device coupled to a router.