Automated Firewall Rule Generation for Multi-Tenant Cloud Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous hybrid cloud environments, manual configuration of firewalls is required to manage access rules, leading to inefficiencies and challenges in automating the creation of a whitelist of allowed rules for secure interconnectivity between different cloud systems while maintaining tenant isolation.

Innovation Solution

An algorithmic approach to generate firewall port access rules and unique IP address ranges for each tenant, allowing only necessary traffic between compute nodes of the same tenant across different cloud providers, with automated IP address management and application of rules to ensure secure and efficient interconnectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual configuration of firewalls is used to manage access rules, then security control is maintained, but configuration efficiency and scalability deteriorate

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidmanual configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system automatically generates firewall rules based on tenant information and network policies without requiring manual configuration. The algorithm autonomously creates access rules, IP address ranges, and applies them to compute nodes, enabling the system to self-configure and scale efficiently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention transforms manual configuration parameters into automated algorithmic parameters. By changing from manual rule entry to algorithmic generation based on input parameters (tenant ID, network policies), the system achieves automated scalability while maintaining security control.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If automated firewall rule generation is implemented, then configuration efficiency improves, but security control and precision deteriorate

Engineering Contradiction:
Improveautomation speedVSAvoidaccess rule precision
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system incorporates feedback mechanisms where the generated rules are validated against security policies and tenant configurations. The algorithm receives feedback about policy constraints and adjusts rule generation to ensure precision while maintaining automation speed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Security policies and access control frameworks are established in advance as input parameters. The algorithm uses these pre-defined policies to generate rules, ensuring precision is maintained from the outset while enabling rapid automated configuration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If firewall rules are applied to all IP addresses, then security coverage is maximized, but system complexity and rule management difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments IP addresses into tenant-specific ranges and applies firewall rules at the tenant level rather than managing individual address rules. This segmentation reduces rule management complexity while maintaining comprehensive security coverage through automated tenant-based rule generation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10469448B2Firewall port access rule generation
Publication Date: 2019.11.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10469448B2 patent drawing
  • US10469448B2 patent drawing
  • US10469448B2 patent drawing

AI summary

A method includes generating firewall port access rules between a first cloud system a second cloud system for each tenant of a plurality of tenants. A unique IP address range is generated for each tenant. The firewall port access rules are applied to each IP address.