Gateway Firewall Authentication Controller for BYOD Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures struggle to effectively restrict access to application servers while allowing trusted users seamless access from various devices, balancing security and convenience in a Bring Your Own Device (BYOD) environment.

Innovation Solution

A computer-implemented method using a gateway system that authenticates client devices via digital signatures and manages network tunnels, employing a firewall to control access based on client access lists and entitlement tokens, ensuring only authorized access to application servers within a private network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network level security is enforced by configuring firewalls and access controls, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a controller as an intermediary device that automatically manages firewall configurations and access rights. The controller receives authentication information from clients, determines access rights based on identity and health profiles, and configures the protection device accordingly. This intermediary automates the security enforcement process, eliminating the need for manual firewall configuration and making security transparent to users while maintaining strong security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access rights are dynamically managed based on authentication, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions into a single integrated controller. The controller performs authentication verification, identity profile matching, health profile assessment, and firewall configuration management all in one device. By merging these previously separate functions into a unified system, the patent reduces overall system complexity while maintaining dynamic access control based on authentication status.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If application servers are isolated within private networks, then security is improved, but adaptability deteriorates

Engineering Contradiction:
Improvenetwork isolation securityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control that adapts firewall rules based on real-time authentication results. When a client is authenticated and authorized, the controller dynamically opens specific firewall ports and configurations to allow access to particular application servers. When access is denied or the session ends, the firewall automatically closes those paths. This dynamic approach maintains private network isolation while providing flexible, on-demand access to authorized users.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10979398B2Systems and methods for protecting network devices by a firewall
Publication Date: 2021.04.13 CRYPTZONE NORTH AMERICA
  • US10979398B2 patent drawing
  • US10979398B2 patent drawing
  • US10979398B2 patent drawing

AI summary

Embodiments of the present disclosure help protect network devices from unauthorized access. Among other things, embodiments of the disclosure allow full access to application servers and other network devices that a client is allowed to access, while preventing all access (or even knowledge) of network devices the client is not allowed to access.