Firewall Access Provisioning via Dynamic Rule Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls in network environments often block access to requested resources without proper authentication, leading to redirection issues and inefficient access provisioning for users attempting to access network services.
Innovation Solution
A method and apparatus that determine and communicate rules to a firewall, allowing it to forward data units to destination addresses, and redirect devices when initial access is denied, enabling dynamic rule creation and communication to facilitate access provisioning through a policy server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the firewall blocks access to requested resources without proper authentication, then network security is maintained, but user access provisioning becomes inefficient and causes redirection issues
Solution Approach 1:
The system performs preliminary authentication and rule determination before the firewall blocks access. When a data unit is blocked, the source device receives redirection to an authentication server, which determines appropriate rules in advance and communicates them to the firewall before allowing subsequent access attempts, preventing repeated blocking and improving provisioning efficiency
Solution Approach 2:
The system implements feedback when access is blocked by sending an indication back to the source device that the firewall did not forward the data unit. This feedback mechanism enables the source device to understand the blocking reason and initiate authentication, creating a closed-loop system that resolves the contradiction between security blocking and efficient access provisioning
2Reliability
If the firewall strictly enforces access rules, then network security is improved, but user access to legitimate resources is delayed due to redirection requirements
Solution Approach 1:
Authentication and rule determination are performed in advance before actual data transfer. The source device authenticates with the server and receives rules communicated to the firewall before the user attempts to access resources, eliminating the need for time-consuming redirection loops and reducing access delay while maintaining strict security enforcement
Solution Approach 2:
An authentication server acts as an intermediary between the source device and the firewall. This intermediary determines appropriate rules and communicates them to the firewall, facilitating smooth access provisioning without requiring the source device to repeatedly interact with the firewall through redirection, thereby reducing access delay while maintaining security
Data Source
AI summary
A method may include determining one or more rules and communicating the one or more rules to a firewall, where the firewall receives a data unit and determines, based on the one or more rules, whether to forward the data unit to a destination address; receiving a redirection of a device from the firewall when the firewall determines not to forward the data unit to the destination address; receiving an indication that the firewall did not forward the data unit to the destination address; and determining a new rule to allow the firewall to forward the data unit to the destination address and communicating the new rule to the firewall; and redirecting the device to the destination address.


