Regional Firewall Clustering for Asymmetric Flow Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall technologies in cloud computing environments face challenges in managing asymmetric packet flows, leading to dropped packets due to the inability to share state information across firewalls, which limits network flexibility and efficiency.

Innovation Solution

Implementing a regional firewall clustering system where each firewall registers with a centralized server to share state table information, allowing for asymmetrical flows and determining a cluster delay interval based on round-trip time to buffer packets with unknown session states until synchronized information is received.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If firewalls operate independently without state sharing, then device complexity is reduced, but packet forwarding reliability deteriorates due to dropped packets in asymmetric flows

Engineering Contradiction:
Improvefirewall operation complexityVSAvoidpacket forwarding reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges the state tables of multiple firewalls into a shared cluster-wide state table accessible by all firewalls in the cluster. This allows firewalls to cooperate on packet filtering decisions while maintaining individual operational simplicity, resolving the contradiction between device complexity and reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a cluster master firewall as an intermediary that manages state table synchronization and coordinates packet forwarding decisions among cluster members. This intermediary enables reliable asymmetric flow handling without requiring complex peer-to-peer communication between all firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls share state information across the cluster, then packet forwarding reliability improves, but loss of time increases due to synchronization delays

Engineering Contradiction:
Improvestate information accuracyVSAvoidstate synchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-synchronizes state table information to all firewalls in the cluster before asymmetric flows occur. By having state information available in advance at all firewalls, the system eliminates synchronization delays during packet forwarding, resolving the contradiction between reliability and time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic state table updates where the cluster master firewall pushes state changes to members only when necessary, rather than continuous synchronization. This dynamic approach minimizes synchronization time while maintaining state information accuracy.

Inventive Principle:
Principle #15Dynamics

3Reliability

If firewalls buffer packets with unknown session states, then packet forwarding reliability improves, but loss of time increases due to buffering delays

Engineering Contradiction:
Improvepacket delivery completenessVSAvoidpacket buffering time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a buffering mechanism with a predefined time interval threshold. Packets are buffered only for the minimum necessary duration to allow state synchronization, rather than indefinite buffering. This partial buffering approach ensures reliable packet delivery while minimizing time loss.

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If regional firewall clustering is implemented, then adaptability improves for asymmetric flows, but device complexity increases due to cluster management overhead

Engineering Contradiction:
Improveasymmetric flow handling capabilityVSAvoidcluster management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall cluster into a master firewall responsible for state management and member firewalls responsible for packet forwarding. This segmentation allows the system to handle asymmetric flows adaptively while distributing complexity across specialized roles rather than requiring all firewalls to perform all functions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10237238B2Regional firewall clustering in a networked computing environment
Publication Date: 2019.03.19 KYNDRYL INC
  • US10237238B2 patent drawing
  • US10237238B2 patent drawing
  • US10237238B2 patent drawing

AI summary

An approach for regional firewall clustering for optimal state-sharing of different sites in a virtualized/networked (e.g., cloud) computing environment is provided. In a typical embodiment, each firewall in a given region is informed of its peer firewalls via a registration process with a centralized server. Each firewall opens up an Internet protocol (IP)-based communication channel to each of its peers in the region to share state table information. This allows for asymmetrical firewall flows through the network and allows routing protocols to ascertain the best path to a given destination without having to take firewall placement into consideration.