Firewall Connection Authorization via Telephone Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access devices with firewalls face security risks due to the need to keep specific ports open for incoming connections, allowing unauthorized access from the public data network.

Innovation Solution

Implementing a method where incoming connections through the firewall are initially blocked, and only allowed after a positive identification feature is checked via a call or SMS, using a telephone number or identifier as the identification feature, ensuring secure and authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If specific ports are kept open for incoming connections, then accessibility and ease of operation are improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary identification and authorization checks via telephone call or SMS before allowing any incoming connections through the firewall. The network access device verifies the caller's identity using stored identification data (telephone numbers, PINs, passwords) and only releases the firewall for authorized connections after successful verification, preventing unauthorized access before it can occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces telephone network communication (calls and SMS messages) as an intermediary authorization channel between the potential connector and the network access device. This intermediary mechanism allows the firewall to maintain its protective blocking state while providing a secure verification path for legitimate connections, resolving the conflict between security and accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the firewall blocks all incoming connections, then security is improved, but accessibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The firewall transitions from a static blocking state to a dynamic state based on authorization results. The system maintains default blocking behavior for security but dynamically opens the firewall for specific authorized connections after successful telephone-based verification. This dynamic adaptation allows the firewall to provide both security and accessibility as needed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses telephone communication as a feedback mechanism where the network access device receives authorization requests, verifies identification data, and responds by either allowing or blocking connections. This feedback loop enables the firewall to make intelligent decisions about connection permissions based on verified authorization, balancing security with accessibility

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2323334B1Approval of a connection through a firewall of a network access device
Publication Date: 2015.01.21 VODAFONE HOLDING GMBH
  • EP2323334B1 patent drawingFigure 1

AI summary

The method involves providing a packet-based data connection over the public data network (18) by a net address (42) which is provided to a network access device (22). A telephone number is provided to the network access device through a telecommunication network (10,14). A blocked connection (84) is released by a releasing device (58). An independent claim is also included for a network access device with a telecommunication network.