Firewall Verification Unit for Application Layer Message Conformity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard firewalls are limited in their ability to provide comprehensive security for the application layer of communication models, primarily relying on pattern or signature recognition, which does not adequately address the security needs of critical applications.

Innovation Solution

A firewall system that includes a verification unit for comparing messages with reference data to detect conformity, generating alert signals for non-conforming messages, and an alert signal management device to implement protective actions, specifically designed to control messages at the application layer of the OSI model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard firewalls use pattern or signature recognition for application layer security, then device complexity is reduced and ease of operation is improved, but security reliability is insufficient for critical applications

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining reference data including predetermined messages and permitted values for fields before message verification occurs. The verification unit compares incoming messages against these pre-established reference data, allowing the system to perform comprehensive security checks without adding complexity to the real-time verification process. This preparation of reference data in advance enables reliable security verification while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If firewalls perform comprehensive message content analysis for application layer security, then security reliability is improved, but processing speed and productivity decrease

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmessage processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the message verification process into distinct components: the verification unit handles the actual message content comparison, while the central unit manages alert signal generation. This segmentation allows the verification unit to focus efficiently on comparing messages against reference data, improving processing speed while maintaining comprehensive security analysis through the coordinated operation of specialized units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback through the alert signal mechanism. When the verification unit detects a lack of conformity between a message and reference data, it triggers an alert signal generated by the central unit. This feedback loop enables the system to quickly identify and respond to security issues without requiring continuous comprehensive analysis of every message, thus improving processing efficiency while maintaining security reliability.

Inventive Principle:
Principle #23Feedback

3Reliability

If firewalls monitor all messages between communication elements, then security coverage is improved, but loss of time for message processing increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by having the verification unit recognize and compare only specific messages that match predetermined patterns in the reference data. Rather than performing exhaustive analysis on every single message, the system focuses verification efforts on messages that require security checking based on their recognition against reference data. This selective approach maintains comprehensive security coverage for relevant messages while reducing unnecessary processing time for other messages.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230328035A1Method and firewall configured to monitor messages transiting between two communication elements
Publication Date: 2023.10.12 MBDA FRANCE
  • US20230328035A1 patent drawing
  • US20230328035A1 patent drawing

AI summary

A firewall includes a verification unit for comparing messages transiting between the two communication elements with data, called reference data, contained in a database and for detecting, where applicable, a lack of conformity of a message in transit with respect to the reference data. The reference data includes predetermined messages and at least authorized values for fields of the predetermined messages. A central unit for generates an alert signal in the event of the verification unit detecting a lack of conformity of a message in transit. A transmission interface is configured to transmit any alert signal to at least one alert signal management device, which will generate an appropriate protective action when an alert signal is generated.