Firewall Hardware Logic Device Protocol Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls are vulnerable to attacks that exploit flaws in the complex protocol stack, leading to potential control by attackers, and existing hardware solutions are limited to lower protocol layers, making them ineffective against higher-level protocol attacks.

Innovation Solution

Implementing a hardware logic device that ensures communication with the firewall uses a simple protocol handled by simple software, examining packets for compliance with a defined firewall protocol, and using fibre optic networking for high-speed, reliable data transmission, while keeping complex protocol stack handling separate to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a complex protocol stack is used in the firewall, then the firewall can handle higher-level protocols and provide stronger security checks, but the firewall becomes vulnerable to attacks that exploit flaws in the protocol stack

Engineering Contradiction:
Improvesecurity strengthVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the protocol handling into two separate paths: a simple protocol stack for handling communication with external computers (which cannot be exploited), and the complex protocol stack for handling internal network traffic (which provides strong security checks). This segmentation isolates the vulnerability risk from the security check functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A simple protocol stack acts as an intermediary between external computers and the complex protocol stack. This intermediary handles all external communication in a way that cannot be exploited, while still allowing the complex protocol stack to perform thorough security checks on the traffic it processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a simple protocol stack is used in the firewall, then the firewall is resistant to attacks but can only perform limited security checks

Engineering Contradiction:
Improveresistance to attacksVSAvoidsecurity check capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system segments protocol handling into two distinct paths: a simple protocol stack for external communication (providing attack resistance) and a complex protocol stack for internal security checks (providing comprehensive validation). Each stack operates in its designated domain, allowing both simplicity and comprehensiveness to coexist.

Inventive Principle:
Principle #1Segmentation

3Productivity

If hardware logic is used to implement the firewall, then the firewall achieves high performance but can only effectively filter lower-level protocols

Engineering Contradiction:
Improveperformance speedVSAvoidprotocol layer coverage
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The hardware logic device acts as an intermediary that enforces a simple protocol format at the hardware level, ensuring high-speed processing. This simple protocol serves as a foundation that works in conjunction with software-based complex protocol stacks to achieve both high performance and comprehensive protocol layer coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex hardware logic that would attempt to handle all protocol layers directly with a simpler hardware logic that enforces basic protocol structure. This substitution allows software components to handle higher-level protocol complexity, achieving both speed and versatility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP1932313B1Communications systems firewall
Publication Date: 2019.06.12 QINETIQ LTD
  • EP1932313B1 patent drawingFigure 1~2
  • EP1932313B1 patent drawingFigure 3~4
  • EP1932313B1 patent drawingFigure 5~6

AI summary

Methods, apparatus, programs. and signals for providing communications network security. The approach is based on using established "standard" protocols, but packets (or cells or frames) are deliberately malformed by the sender, optionally according to a predetermined rule (for example by inverting a packet check digit). A filter forwards only packets identified as being invalid, optionally in accordance with the rule; packets which are valid with respect to the "standard" protocol are dropped. The filter is preferably implemented in hardware to mitigate the risk of its being compromised by a malicious attack.