Firewall Change Request Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network firewalls face challenges in managing change requests efficiently, leading to redundant and time-consuming tasks for administrators, and require manual updates and authentication processes that are not intuitive or robust.

Innovation Solution

A method and system for managing firewall change requests through a change request interface with multiple form types, including requestor identification, IP address information, and implementation schedules, which allows for authentication, queue management, and notification, along with communication with firewalls for policy and rule updates, and topology maintenance to streamline the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates and authentication processes are used for firewall change requests, then administrators can control and verify each change, but the process becomes time-consuming and redundant

Engineering Contradiction:
Improvefirewall change controlVSAvoidadministrative processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the firewall change management process into distinct functional modules: request submission interface, authentication module, queue management system, and firewall communication interface. This segmentation allows each component to be optimized independently while maintaining overall process control and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by implementing automated authentication through single sign-on before the actual change request processing. Change requests are pre-validated and queued with authentication status, so that when administrators review them, the verification work has already been completed, reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If multiple change request forms and manual processing are used, then detailed information can be collected, but the administrative burden increases

Engineering Contradiction:
Improvechange request detailsVSAvoidadministrative workload
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system implements a universal change request interface that handles multiple types of firewall changes (rule additions, modifications, deletions, IP address changes) through a single standardized form structure. This multi-functional interface collects all necessary information in a consistent format, eliminating the need for administrators to process different form types manually and reducing operational burden while preserving complete change request details.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates structured digital copies of change request information in a standardized format that can be automatically processed, stored, and transmitted. Instead of manual handling of paper or unstructured digital forms, the system uses templated form copies that automatically capture and organize all required information, reducing administrative burden while maintaining data completeness.

Inventive Principle:
Principle #26Copying

3Productivity

If automated queue management and notification systems are implemented, then processing efficiency improves, but system complexity increases

Engineering Contradiction:
Improvechange request processing speedVSAvoidmanagement system structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary queue management component that sits between request submission and administrator review. This intermediary automatically manages the flow of change requests, tracks processing status, and handles notifications. While this adds a system component, it acts as a simple mediator that automates routine tasks without requiring complex decision-making logic, thus improving productivity with manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If comprehensive authentication and approval processes are used, then security is enhanced, but the implementation time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidchange implementation time
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs authentication and validation actions preliminarily through single sign-on integration and automated form validation before the change request enters the approval queue. User credentials are verified in advance, and request completeness is checked automatically, so that the actual approval and implementation process can proceed more quickly while maintaining enhanced security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9154462B2Methods, systems, and computer program products for managing firewall change requests in a communication network
Publication Date: 2015.10.06 AT&T INTELLECTUAL PROPERTY I L P
  • US9154462B2 patent drawing
  • US9154462B2 patent drawing
  • US9154462B2 patent drawing

AI summary

A method of managing firewall change requests for a communication network includes providing a change request interface comprising a plurality of change request form types, each request form including an interface for entering requestor identification information, Internet Protocol (IP) address information, change implementation schedule information, and submission information specifying any requestor instructions for implementing the change, receiving completed change request forms from at least one requestor, arranging the completed change request forms in a request queue, and presenting the request queue to at least one administrator responsible for implementing firewall changes in the communication network.