Firewall Access Control via Database Mediator for Mobile Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network firewalls are unable to predict and configure all possible addresses used by mobile nodes, leading to potential security vulnerabilities as they may allow unauthorized access from hostile nodes using varying sub-network addresses.

Innovation Solution

A method and system that updates a firewall node with logical names for mobile nodes, receives packets, obtains source addresses from a database, and checks if the source address is allowed, admitting packets only if it belongs to the authorized addresses, thereby enhancing security and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the firewall configures filter rules for all possible addresses that a mobile node may use, then access control for mobile nodes is improved, but the device complexity increases due to the inability to predict all possible sub-network addresses

Engineering Contradiction:
Improveaccess control for mobile nodesVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a database node as an intermediary component that stores and provides authorized addresses for mobile nodes. Instead of the firewall maintaining complex configuration rules for all possible addresses, the database node serves as a mediator that supplies the necessary address information, simplifying the firewall's operation while ensuring comprehensive access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by having mobile nodes register their authorized addresses with the database node before accessing the protected network. The firewall queries the database node in advance to obtain the list of authorized addresses for each mobile node, allowing the firewall to make accurate access decisions without maintaining complex configuration rules.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the firewall allows a wide range of addresses to accommodate mobile nodes, then adaptability is improved, but security deteriorates due to exposure to attacks from hostile nodes

Engineering Contradiction:
Improvesupport for mobile nodesVSAvoidsecurity vulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by having mobile nodes dynamically update their authorized addresses in the database node whenever they change sub-networks. The firewall continuously queries the database node for the current authorized addresses, ensuring that access is granted only to addresses that are currently registered, thus maintaining security while supporting mobile node adaptability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses preliminary action by requiring mobile nodes to pre-register their authorized addresses with the database node before accessing the protected network. This advance registration ensures that the firewall has accurate, up-to-date information about which addresses are authorized, preventing hostile nodes from exploiting address ranges while maintaining support for mobile node mobility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8239930B2Method for controlling access to a network in a communication system
Publication Date: 2012.08.07 NOKIA TECHNOLOGIES OY
  • US8239930B2 patent drawing
  • US8239930B2 patent drawing
  • US8239930B2 patent drawing

AI summary

The invention relates to a method for controlling access to a private network. To a firewall node are updated logical names for mobile nodes allowed to communicate with nodes in the private network. A packet is received to the firewall node from an external network, the packet being addressed to a first node within the private network. The source address is obtained from the packet. Addresses associated with the logical names are obtained from a database node. It is checked whether the source address belongs to the addresses obtained. The packet is admitted to the private network, if the source address belongs to the addresses obtained.