Firewall System with Signature Validation Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls are vulnerable to errors and attacks due to their reliance on complex communication protocols, which can lead to security weaknesses and performance impairments, especially when intercepting higher protocol layers or using simple communication media.

Innovation Solution

A firewall system incorporating signature validation hardware that operates at the software application level, using high-performance media links and digital circuitry to validate data signatures, thereby avoiding exposure to complex protocols and ensuring high security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall uses complex communication protocols to intercept higher protocol layers, then security effectiveness is improved, but device complexity and vulnerability to attacks increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex protocol handling functionality from the firewall itself and relocates it to external host systems. The firewall is reduced to a simple bridge that only handles low-level data link layer protocols, while the host systems perform the complex network layer and above protocol processing. This extraction eliminates the firewall's vulnerability to protocol stack flaws while maintaining security effectiveness through hardware-based signature validation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces host systems as intermediary components between the firewall and the network. These hosts act as mediators that handle complex protocol interactions, allowing the firewall to remain simple and secure while still enabling sophisticated security checks through the hosts' protocol processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a firewall uses software application level checks, then security coverage is improved, but performance and robustness deteriorate due to software vulnerabilities

Engineering Contradiction:
Improvesecurity coverageVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based security checks with hardware-based signature validation. Instead of using software applications to inspect and validate data at the application layer, the firewall uses dedicated hardware circuits to perform cryptographic signature verification. This substitution provides both the security coverage of application-level checks and the performance/robustness of hardware processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a firewall intercepts all protocol layers, then security strength is improved, but processing time and complexity increase

Engineering Contradiction:
Improvesecurity strengthVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the protocol processing function across multiple independent components: the firewall handles only the data link layer (simple forwarding), while host systems handle network layer and above protocols (complex processing). This segmentation allows parallel processing where the firewall performs fast hardware-based signature validation simultaneously with the hosts performing protocol processing, thereby maintaining security strength while reducing overall processing time.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8108679B2Firewall system
Publication Date: 2012.01.31 QINETIQ LTD
  • US8108679B2 patent drawing
  • US8108679B2 patent drawing
  • US8108679B2 patent drawing

AI summary

A firewall system employs signature validation hardware communicating via low level communication protocols and with inner and outer host computers, which have network protocol stacks and for implementing complex communication protocols with remote source and destination computers. The source computer has data checker and signature functionalities, which respectively check data and generate digital signatures for data to be transmitted. The inner host computer receives transmitted data and converts it to a lower protocol level at which the hardware operates. The hardware uses digital circuitry for protocols and checking. It validates signatures in data at a software application level, but only requires protocols that are simple and low level. The firewall system communicates with the source and destination computers via high performance connection media. The hardware itself communicates with the host computers also via high performance connection media, and avoids involvement with complex communications protocols which make other firewalls vulnerable.