Firewall Offloading via Dual Network Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As firewall rules and security countermeasures become increasingly complex, there is a need for a firewall system that can offload monitoring of network flows to other networking hardware, reducing the processing burden on the firewall.

Innovation Solution

A firewall system that provides two network paths for network flows: one through the firewall on a host device and another through alternative hardware or software that has analyzed and allowed the network flows. The system can transfer network flows between these paths based on the status of each flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall rules and security countermeasures become increasingly complex, then network security is improved, but processing burden on the firewall increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing burden on firewall
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network flow handling into two distinct paths: a first path through the firewall for initial analysis and a second path through alternative hardware for approved flows. This segmentation allows the firewall to focus only on critical security decisions while offloading routine traffic handling to dedicated networking hardware, thereby reducing processing burden while maintaining security through the initial firewall analysis stage

Inventive Principle:
Principle #1Segmentation

2Reliability

If firewall rules and security countermeasures become increasingly complex, then network security is improved, but system performance deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork flow processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts approved network flows from the firewall processing path and redirects them to alternative hardware systems. By taking out the bulk of approved traffic from the firewall's processing burden, the system maintains high security through initial firewall analysis while significantly improving overall processing speed through hardware acceleration for the majority of traffic

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If all network flows are monitored by the firewall, then network security is improved, but processing load on the firewall increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing load on firewall
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent introduces alternative networking hardware as an intermediary system that handles network flows after initial firewall analysis. This intermediary accepts approved flows from the firewall and processes them independently, allowing the firewall to maintain comprehensive security monitoring for all flows through initial analysis while reducing its processing load by delegating subsequent handling to the intermediary hardware system

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250202865A1Firewall offloading
Publication Date: 2025.06.19 SOPHOS LTD
  • US20250202865A1 patent drawing
  • US20250202865A1 patent drawing
  • US20250202865A1 patent drawing

AI summary

A firewall system provides two network paths for network flows: one path through a firewall on a host device and another path through an alternative hardware or software system that handles network flows that have been analyzed and allowed by the firewall. The firewall system can then transfer network flows between the two paths according to the status of each network flow.