Firewall Port Mapping for Trusted Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face challenges in distinguishing between trusted and untrusted sources, leading to unnecessary stringent security measures being applied to all access points, including those in secure locations, due to the vulnerability of IP and MAC addresses to forgery and the complexity of digital certificate verification processes.

Innovation Solution

Implementing a firewall system that identifies secure locations and assigns reserved port addresses, allowing messages from trusted sources to be mapped to these addresses, while blocking or applying different security measures to messages not from secure sources, thereby distinguishing between trusted and untrusted communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates and encryption are used to verify trusted sources, then security reliability is improved, but device complexity and ease of operation deteriorate due to key exchanges and third-party verification requirements

Engineering Contradiction:
Improvesecurity verificationVSAvoidsecurity procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network interface into trusted and untrusted categories, applying different security measures to each segment. Trusted interfaces (physically secured) receive simplified handling, while untrusted interfaces (publicly accessible) receive stringent verification, eliminating the need for complex security procedures across all interfaces

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different locations/interfaces. Physically secured interfaces are granted trusted status with minimal security overhead, while unsecured interfaces require full security verification. This local differentiation resolves the contradiction by tailoring security complexity to the actual threat level at each interface

Inventive Principle:
Principle #3Local quality

2Reliability

If stringent security measures are applied to all access points, then security reliability is improved, but ease of operation deteriorates due to cumbersome verification procedures

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess procedure simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides access points into two segments: trusted interfaces in physically secured locations and untrusted interfaces in public locations. This segmentation allows simplified access for trusted sources while maintaining stringent security for untrusted sources, resolving the contradiction between universal security and operational simplicity

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If IP addresses and MAC addresses are used for device identification, then device distinguishability is improved, but reliability deteriorates due to address forgery and spoofing vulnerabilities

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidtrust verification
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a physically secured location as an intermediary trust anchor. Instead of relying solely on address-based identification (which can be forged), the system uses the physical security of the location as a mediator to establish trust. Messages from devices in secured locations are automatically trusted, eliminating the reliability issue of address spoofing

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8051474B1Method and apparatus for identifying trusted sources based on access point
Publication Date: 2011.11.01 AVAYA INC
  • US8051474B1 patent drawing
  • US8051474B1 patent drawing
  • US8051474B1 patent drawing

AI summary

Methods and systems for distinguishing between sources of messages at a computer system resource are provided. In particular, messages are classified according to the physical interface at which the messages are received. A message received at an interface connected to a trusted source has the port address associated with that message mapped to a predefined port address by a firewall computer, before being passed to a server computer or other system resource. A message received at an interface that is connected to an untrusted source is passed to the server computer using the original port address. The server computer may then treat messages associated with one of the reserved port addresses differently from messages associated with a non-reserved port address.