Geographic Filter for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall technologies are limited in their ability to enforce geographic-based network access control due to their reliance on manual, time-consuming processes and the inefficiency of handling large rule sets, particularly in enterprise networks, which hinders effective geographic security controls.

Innovation Solution

A geographic filter device that processes IP packets based on pre-configured rule sets using geographic location data, allowing for real-time classification and action on network traffic, reducing the need for extensive rule sets and enabling efficient geographic-based access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls use manual rule-set configuration for geographic-based access control, then network security can be enforced, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating firewall rules from geographic location data before traffic filtering is needed. The geographic filter device pre-processes location information and converts it into actionable firewall rules, eliminating the need for manual, time-consuming rule configuration while maintaining reliable network security enforcement.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If firewalls handle large rule sets for comprehensive geographic coverage, then more regions can be controlled, but processing efficiency decreases

Engineering Contradiction:
Improvegeographic coverageVSAvoidpacket processing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The invention extracts only the essential geographic location information from incoming network traffic and uses it to determine access control decisions. By taking out just the necessary geographic data rather than processing complete rule sets, the system achieves comprehensive geographic coverage while maintaining high packet processing speed and avoiding the efficiency loss associated with handling large rule sets.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If manual processes are used for geographic-based access control, then implementation is simpler, but scalability to enterprise networks is hindered

Engineering Contradiction:
Improveimplementation simplicityVSAvoidscalability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The geographic filter device performs self-service by automatically obtaining geographic location data, generating appropriate firewall rules, and enforcing access control policies without requiring manual intervention. This automation maintains implementation simplicity while enabling scalability to enterprise networks, as the system can independently handle increasing volumes of traffic and geographic regions without proportionally increasing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9537825B2Geographic filter for regulating inbound and outbound network communications
Publication Date: 2017.01.03 IORHYTHM
  • US9537825B2 patent drawing
  • US9537825B2 patent drawing
  • US9537825B2 patent drawing

AI summary

A system and method for regulating and analyzing inbound and outbound communications in and between computer networks on the basis of geographic security assertions are provided. Geographic information is collected, optimized, and shared between network objects to enforce network access control on the basis of configurable security assertions. Security assertions are configured and metrics displayed using maps and other geographic data in a graphical user interface.