Firewall Interface Segmentation for Secure Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid cloud environments, existing solutions fail to securely expose a subset of services from devices inside a private network to devices outside, risking unauthorized access and compromising privacy due to the lack of granular control over VPN connections.

Innovation Solution

A software component is deployed outside the private network to expose a limited interface for requesting services from a subset of devices inside the firewall, which forwards requests to a gateway for secure processing, ensuring only authorized devices can access specific services and maintaining a whitelist for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a VPN connection is established to provide devices outside the private network authorized access through the firewall, then access to devices inside the private network is enabled, but security protection is compromised as the device can access any device without firewall protection

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the service access by creating a dedicated interface that exposes only specific services from a subset of devices inside the private network to outside devices. This segmentation allows selective exposure of services (e.g., DNS, DHCP) while keeping other services protected, thereby maintaining security while enabling necessary access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that sits between the outside devices and the private network devices. This intermediary receives service requests from outside devices, validates them against the exposed service set, and forwards only legitimate requests to the appropriate inside devices. This mediator layer preserves firewall security while enabling controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the firewall or VPN server is manually configured to limit access to specific devices, data, software, or resources, then security is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by allowing the interface to automatically manage service exposure configurations. The system can dynamically determine which services to expose and to which outside devices based on predefined policies or service requirements, eliminating the need for manual firewall rule configuration and reducing administrative complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal interface that can handle multiple service types (DNS, DHCP, and other network services) through a single configuration mechanism. This multi-functional interface replaces the need for separate manual configurations for each service and device, simplifying the overall configuration process while maintaining granular security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual configuration is used to limit VPN access, then security control is achieved, but time consumption and operational efficiency are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the interface with the set of services to be exposed and the policies for access control before operational use. This advance configuration eliminates the need for time-consuming manual adjustments during operations, as the system is already optimized for secure service exposure when deployed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that automatically monitor and adjust service exposure based on actual usage patterns and security requirements. The system can detect when services are being accessed and dynamically adjust the interface configurations, reducing the need for manual intervention and improving operational efficiency while maintaining security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9954824B2Exposing an interface to devices outside a network for requesting a subset of services provided by devices inside the network
Publication Date: 2018.04.24 ORACLE INT CORP
  • US9954824B2 patent drawing
  • US9954824B2 patent drawing
  • US9954824B2 patent drawing

AI summary

A method includes extending an interface, to a device outside a firewall, for requesting a service performed by a device inside the firewall. The interface is extended using a software component, executing outside the firewall, which executes a separate interface to accept requests for services from devices outside the firewall. The separate interface, exposed outside the firewall, is configured for accepting a subset of the services available inside the firewall.