Firewall Port Mapping for Trusted Source Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer networks face challenges in distinguishing between trusted and untrusted sources, leading to unnecessary stringent security measures being applied to all access points, including those in secure locations, due to the vulnerability of IP and MAC addresses to forgery and the complexity of digital certificate verification processes.
Innovation Solution
Implementing a firewall system that identifies secure locations and assigns reserved port addresses, allowing messages from trusted sources to be mapped to these addresses, while blocking or applying different security measures to messages not from secure sources, thereby distinguishing between trusted and untrusted communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificates and encryption are used to verify trusted sources, then security reliability is improved, but device complexity and ease of operation deteriorate due to key exchanges and third-party verification requirements
Solution Approach 1:
The patent segments the network interface into trusted and untrusted categories, applying different security measures to each segment. Trusted interfaces (physically secured) receive simplified handling, while untrusted interfaces (publicly accessible) receive stringent verification, eliminating the need for complex security procedures across all interfaces
Solution Approach 2:
The patent applies different security qualities to different locations/interfaces. Physically secured interfaces are granted trusted status with minimal security overhead, while unsecured interfaces require full security verification. This local differentiation resolves the contradiction by tailoring security complexity to the actual threat level at each interface
2Reliability
If stringent security measures are applied to all access points, then security reliability is improved, but ease of operation deteriorates due to cumbersome verification procedures
Solution Approach 1:
The patent divides access points into two segments: trusted interfaces in physically secured locations and untrusted interfaces in public locations. This segmentation allows simplified access for trusted sources while maintaining stringent security for untrusted sources, resolving the contradiction between universal security and operational simplicity
3Measurement precision
If IP addresses and MAC addresses are used for device identification, then device distinguishability is improved, but reliability deteriorates due to address forgery and spoofing vulnerabilities
Solution Approach 1:
The patent introduces a physically secured location as an intermediary trust anchor. Instead of relying solely on address-based identification (which can be forged), the system uses the physical security of the location as a mediator to establish trust. Messages from devices in secured locations are automatically trusted, eliminating the reliability issue of address spoofing
Data Source
AI summary
Methods and systems for distinguishing between sources of messages at a computer system resource are provided. In particular, messages are classified according to the physical interface at which the messages are received. A message received at an interface connected to a trusted source has the port address associated with that message mapped to a predefined port address by a firewall computer, before being passed to a server computer or other system resource. A message received at an interface that is connected to an untrusted source is passed to the server computer using the original port address. The server computer may then treat messages associated with one of the reserved port addresses differently from messages associated with a non-reserved port address.


