Firewall Virtual Interface Encoding for Secure Router Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls face challenges in transmitting additional information to a secure network without degrading security, as modifying IP packets can be hazardous and adding new protocol layers is costly and complex.

Innovation Solution

A method and system that utilize a firewall with virtual interfaces to transmit authorized packets, allowing specific information to be associated with these interfaces and transmitted without modifying the packets, enabling the router to deduce this information for efficient routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the firewall transmits additional information by modifying the IP packet, then the router can obtain useful information for routing, but the security level may be degraded and the manipulation may be hazardous

Engineering Contradiction:
Improveinformation transmission to routerVSAvoidsecurity level
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The invention segments the information transmission by creating multiple virtual interfaces, each associated with specific information items. Instead of modifying the IP packet directly, the firewall transmits the packet through different virtual interfaces based on the information to be conveyed, with each interface representing a distinct information category or routing requirement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual interfaces act as intermediaries between the firewall and the router. The firewall selects appropriate virtual interfaces based on the packet characteristics, and the router deduces the specific information from the received virtual interface, avoiding direct packet modification while still enabling information transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If a new protocol layer is added to transmit additional information from the firewall to the router, then information can be transmitted, but costly and complex modifications to the transport units are required

Engineering Contradiction:
Improveinformation transmission capabilityVSAvoidprotocol layer complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The virtual interfaces provide a universal mechanism that handles multiple information types and routing scenarios without requiring separate protocol layers for each case. The existing interface infrastructure is extended to serve multiple functions: standard packet forwarding, information encoding through interface selection, and router guidance, all within the same architectural framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If the router obtains information from complex computation on received data, then additional information can be extracted, but the router performance is degraded

Engineering Contradiction:
Improveinformation extraction capabilityVSAvoidrouter performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The firewall performs the information classification and selection action in advance, before the packet reaches the router. By determining which virtual interface to use based on the packet characteristics and associated information items, the firewall prepares the packet for efficient router processing. The router then only needs to identify the virtual interface and deduce the information, rather than performing complex analysis on the packet content.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8341719B2Secure transmitting method, a system, a firewall, and a router using the method
Publication Date: 2012.12.25 SAFRAN ELECTRONICS & DEFENSE (FR)
  • US8341719B2 patent drawing
  • US8341719B2 patent drawing
  • US8341719B2 patent drawing

AI summary

Data packets are transmitted in a secure manner from an external network to a secure network. The secure network and the external network are interconnected via a firewall comprising a first interface with the external network and a second interface with the secure network. The firewall provides, over the second interface, a plurality of virtual interfaces. An association between items of specific information of the firewall and said virtual interfaces is stored in the firewall and in the secure network. It is determined whether to authorize the transmission of a packet received from the external network to the secure network on the basis of predefined security criteria. If the received packet is authorized, an item of specific information is selected to be transmitted to the secure network with the authorized packet. A virtual interface is then determined as a function of the item of specific information selected on the basis of the association. The authorized packet is then transmitted via the determined virtual interface. Thus, on reception of the packet in the secure network, the item of specific information can be deduced from the virtual interface through which the packet is received, on the basis of the association.