Firewall Access Provisioning via Dynamic Rule Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in network environments often block access to requested resources without proper authentication, leading to redirection issues and inefficient access provisioning for users attempting to access network services.

Innovation Solution

A method and apparatus that determine and communicate rules to a firewall, allowing it to forward data units to destination addresses, and redirect devices when initial access is denied, enabling dynamic rule creation and communication to facilitate access provisioning through a policy server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the firewall blocks access to requested resources without proper authentication, then network security is maintained, but user access provisioning becomes inefficient and causes redirection issues

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess provisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication and rule determination before the firewall blocks access. When a data unit is blocked, the source device receives redirection to an authentication server, which determines appropriate rules in advance and communicates them to the firewall before allowing subsequent access attempts, preventing repeated blocking and improving provisioning efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback when access is blocked by sending an indication back to the source device that the firewall did not forward the data unit. This feedback mechanism enables the source device to understand the blocking reason and initiate authentication, creating a closed-loop system that resolves the contradiction between security blocking and efficient access provisioning

Inventive Principle:
Principle #23Feedback

2Reliability

If the firewall strictly enforces access rules, then network security is improved, but user access to legitimate resources is delayed due to redirection requirements

Engineering Contradiction:
Improvefirewall security enforcementVSAvoidaccess delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication and rule determination are performed in advance before actual data transfer. The source device authenticates with the server and receives rules communicated to the firewall before the user attempts to access resources, eliminating the need for time-consuming redirection loops and reducing access delay while maintaining strict security enforcement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication server acts as an intermediary between the source device and the firewall. This intermediary determines appropriate rules and communicates them to the firewall, facilitating smooth access provisioning without requiring the source device to repeatedly interact with the firewall through redirection, thereby reducing access delay while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9350704B2Provisioning network access through a firewall
Publication Date: 2016.05.24 JUNIPER NETWORKS INC
  • US9350704B2 patent drawing
  • US9350704B2 patent drawing
  • US9350704B2 patent drawing

AI summary

A method may include determining one or more rules and communicating the one or more rules to a firewall, where the firewall receives a data unit and determines, based on the one or more rules, whether to forward the data unit to a destination address; receiving a redirection of a device from the firewall when the firewall determines not to forward the data unit to the destination address; receiving an indication that the firewall did not forward the data unit to the destination address; and determining a new rule to allow the firewall to forward the data unit to the destination address and communicating the new rule to the firewall; and redirecting the device to the destination address.