Automated Firewall and IPsec Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring firewall and IPsec tools to ensure consistent and effective security policies is complex and prone to errors, leading to vulnerabilities in data security, especially due to the complexity of IPsec terminology and the need for symmetric outbound and inbound security policies.

Innovation Solution

A system and method that provides a user interface to define security rules integrating firewall and connection policies, automatically generating consistent firewall and IPsec rules, and allowing automatic derivation of outbound security policies from inbound policies to ensure matching security suites across computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security personnel manually configure firewall and IPsec rules to implement enterprise security policy, then the security policy can be customized and implemented, but the configuration process becomes complex and tedious, leading to errors and inconsistencies

Engineering Contradiction:
Improvesecurity policy implementation reliabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that automatically generates firewall and IPsec rules from high-level security policies. This intermediary translation layer converts business-level security requirements into technical configuration rules, eliminating the need for security personnel to manually configure complex IPsec parameters and reducing configuration errors while maintaining policy customization capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the security configuration system to automatically generate and coordinate both firewall and IPsec rules without requiring security personnel to manually configure both technologies. The system self-manages the complexity of coordinating overlapping firewall and IPsec technologies, reducing human effort while maintaining reliable security policy implementation

Inventive Principle:
Principle #25Self-service

2Stability of the object's composition

If security personnel coordinate firewall rules and IPsec rules manually, then consistent security policy implementation is achieved, but the process becomes extremely difficult and time-consuming due to overlapping technologies and complex IPsec terminology

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidconfiguration time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically generating coordinated firewall and IPsec rules before deployment. The system pre-coordinates the rules to ensure consistency, eliminating the time-consuming manual coordination process while maintaining stable and consistent security policy implementation across both technologies

Inventive Principle:
Principle #10Preliminary action

3Reliability

If administrators manually establish matching inbound and outbound security policies with symmetric crypto suites, then IPsec security requirements are met, but the process becomes tedious and complex due to the need for symmetric configuration

Engineering Contradiction:
ImproveIPsec security complianceVSAvoidsecurity policy configuration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies asymmetry by allowing asymmetric configuration of inbound and outbound security policies. The system automatically generates symmetric matching crypto suites for IPsec compliance while allowing the high-level security policy configuration to remain asymmetric and flexible. This resolves the contradiction by maintaining IPsec security requirements through automatic symmetric rule generation while simplifying administrator operations through asymmetric policy definition

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS8056124B2Automatically generating rules for connection security
Publication Date: 2011.11.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8056124B2 patent drawing
  • US8056124B2 patent drawing
  • US8056124B2 patent drawing

AI summary

A method and system for creating security policies for firewall and connection policies in an integrated manner is provided. The security system provides a user interface through which a user can define a security rule that specifies both a firewall policy and a connection policy. After the security rule is specified, the security system automatically generates a firewall rule and a connection rule to implement the security rule. The security system provides the firewall rule to a firewall engine that is responsible for enforcing the firewall rules and provides the connection rule to an IPsec engine that is responsible for enforcing the connection rules.