Firewall Ticket Identifier for Automated Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies in accessing network destinations due to unknown security device configurations and the time-consuming process of identifying and reconfiguring multiple security devices to allow packet forwarding, especially when the path through the network is dynamic and involves numerous security devices.

Innovation Solution

A system and method that utilize a ticket identifier within packets to facilitate path testing and access management, where security devices log packet dispositions and automatically reconfigure to permit access, leveraging a self-help portal, access authority, and log server to streamline the process of identifying and modifying security device configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security devices block packets to prevent unauthorized access, then network security is improved, but user access to legitimate destinations becomes difficult and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables security devices to automatically identify and permit legitimate traffic through self-service mechanisms. When a user sends packets with valid ticket identifiers, security devices autonomously log the dispositions and reconfigure their access control lists to permit the traffic, eliminating the need for manual administrator intervention and significantly improving user access ease while maintaining security through automated validation

Inventive Principle:
Principle #25Self-service

2Reliability

If multiple security devices are configured to block packets, then security coverage is improved, but the complexity of identifying and reconfiguring devices increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where security devices automatically log packet dispositions (blocked or permitted) and this information is fed back to the user through a portal. Users can query which security devices blocked their packets and receive automated reconfiguration requests, significantly reducing the complexity of managing multiple security devices while maintaining comprehensive security coverage

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A portal server acts as an intermediary between users and multiple security devices. The portal receives user access requests, coordinates with security devices to identify blocking devices, and manages the reconfiguration process. This intermediary layer abstracts the complexity of multiple security device configurations from both users and administrators

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security devices silently block packets without notification, then security operation is improved, but user troubleshooting capability deteriorates

Engineering Contradiction:
Improvesecurity operationVSAvoidpacket blocking detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system transforms silent blocking into informative feedback by having security devices log packet dispositions and communicate this information back to users through a portal. Users receive specific information about which security devices blocked their packets and why, enabling effective troubleshooting while maintaining secure automated blocking operations

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the 'color' or visibility of blocked packets by attaching ticket identifiers and disposition logs to the packet flow information. This makes previously invisible blocked packets detectable and measurable through the portal interface, allowing users to identify and address blocking issues without compromising security operations

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS20230396586A1Intelligent firewall using identification of valid traffic
Publication Date: 2023.12.07 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US20230396586A1 patent drawing
  • US20230396586A1 patent drawing
  • US20230396586A1 patent drawing

AI summary

In a network in which connections are made, between devices or between network segments, through security devices such as firewalls, a user attempting to contact a destination device may be prevented from doing so by some or all of the security devices, which may silently block packets, sent by the user, addressed to the destination device. The remedying of this inability to contact the destination device may be made more difficult by a lack of knowledge, on the part of the user, regarding which security devices are configured to block the packets. As such, a system and method for managing network access are provided.