Time-Deterministic Firewall Conditional Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls struggle to process packets in real-time due to varying processing times and high loads, leading to delays and backlogs, which are exacerbated by the lack of time budgets in existing firewalls.
Innovation Solution
A method for conditional filtering in time-deterministic firewalls, where packets are processed with a predetermined maximum time (tmax), allowing for early termination and forwarding or discarding of packets, while incomplete packets are buffered for later processing when resources become available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete packet analysis according to all firewall rules is performed, then filtering accuracy and security are improved, but processing time increases and real-time performance deteriorates
Solution Approach 1:
The patent applies preliminary action by establishing a maximum processing time threshold (tmax) in advance before packet processing begins. This pre-defined time limit allows the firewall to make time-deterministic decisions about whether to complete full packet analysis or terminate processing early, resolving the contradiction between thorough filtering and processing speed.
Solution Approach 2:
The patent implements dynamics by making the packet processing behavior adaptive based on real-time conditions. The firewall dynamically adjusts its processing depth based on the current load, priority level of packets, and available resources, allowing it to balance between complete analysis and fast forwarding on a case-by-case basis rather than using a fixed approach.
2Measurement precision
If variable processing time is allowed, then complete packet evaluation is possible, but packet flow prediction and network planning become difficult
Solution Approach 1:
The patent applies parameter changes by introducing a maximum processing time parameter (tmax) that can be configured and adjusted. This parameter transforms the variable processing time into a bounded, predictable parameter, allowing network systems to plan for worst-case scenarios while maintaining the ability to complete evaluations when time permits.
3Reliability
If high-priority packets receive complete processing, then security is maintained, but low-priority packets experience excessive delays
Solution Approach 1:
The patent applies local quality by differentiating processing behavior based on packet characteristics and priority levels. Different packet types receive different processing treatments - high-priority packets may receive complete analysis while low-priority packets can be forwarded with reduced processing, allowing each packet to receive the quality of processing it needs rather than uniform treatment.
Solution Approach 2:
The patent implements dynamics through priority-based adaptive processing where the firewall adjusts processing depth based on packet priority levels and current system state. This dynamic approach ensures that critical packets receive thorough processing when needed while allowing the system to maintain overall throughput by reducing processing for less critical packets.
Data Source
AI summary
The invention relates to a method for allowing data packets in a network to arrive at the recipient at definable times. The method requires a firewall in a computer network. Each data packet which is transmitted through the firewall to a recipient is assigned a time budget for processing in the firewall. After the time budget has expired, the firewall performs a firewall action for each data packet, which can be executed as sending to the recipient or discarding the packet. The time budget may be less than the processing time required by the firewall to completely process all filter rules, and thus forms a termination condition for processing the data packet in the firewall.


