Centralized Identity Broker for Distributed Firewall Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security architectures for IoT devices are inadequate, particularly due to limited processing power, memory, and user interface constraints, making it difficult to integrate them into existing client-server security systems, and traditional network access control methods rely on directory agents that may not ensure reliable or timely updates, especially for distributed firewalls.

Innovation Solution

A system that centrally manages user identities and access policies across distributed firewalls using a broker that receives identity awareness data from directory services, posts it to a distributed data repository, and uses this data to establish firewall rules for controlling network traffic, eliminating the need for individual directory agents at each firewall.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional directory agents are used at each firewall for IP-to-user mappings, then firewalls can control network access based on user identities, but connectivity to directory agents may be unreliable and updates may not be timely

Engineering Contradiction:
Improvereliability of directory agent connectivityVSAvoidcomplexity of distributed firewall system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized identity management server as an intermediary between firewalls and directory agents. This server consolidates IP-to-user mapping data and distributes it to multiple firewalls, eliminating the need for each firewall to directly connect to directory agents. The intermediary resolves the contradiction by providing reliable, centralized access to identity data while simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the identity management functionality from multiple distributed directory agents into a single centralized server. Instead of having separate directory agents at each firewall location, the system combines all IP-to-user mapping capabilities in one central repository that serves all firewalls, thereby improving reliability and reducing complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If each firewall maintains its own directory agent for access control, then firewalls can operate independently, but updating all firewalls with latest mappings becomes difficult when new firewalls are deployed

Engineering Contradiction:
Improveease of deploying new firewallsVSAvoidtime to update mappings across firewalls
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The centralized identity management server acts as an intermediary that automatically distributes updated IP-to-user mappings to all firewalls in the network. When new firewalls are deployed or mappings are updated, the central server pushes the latest data to all connected firewalls simultaneously, eliminating manual update processes and reducing the time required to maintain consistent access control across the entire firewall fleet.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If IoT devices are integrated into existing client-server security systems, then network access control can be provided, but limited processing power, memory, and user interface elements make integration difficult

Engineering Contradiction:
Improveease of integrating IoT devicesVSAvoidcomplexity of security system architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex identity management and authentication logic from the IoT devices themselves and places it in the centralized identity management server. IoT devices only need to present their identities for access control decisions, while the heavy lifting of maintaining IP-to-user mappings, authentication policies, and access control logic is performed by the centralized server. This extraction simplifies IoT device integration while maintaining comprehensive security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10951605B2Centrally managing data for distributed identity-based firewalling
Publication Date: 2021.03.16 XAGE SECURITY INC
  • US10951605B2 patent drawing
  • US10951605B2 patent drawing
  • US10951605B2 patent drawing

AI summary

In an embodiment, a computer-implemented method comprises receiving, by at least one broker computing devices, identity awareness data from a plurality of directory services in a federation; posting, by the at least one broker computing device, the identity awareness data to a distributed data repository; establishing, at a networking hardware device having a first type, firewall rules using the identity awareness data from the distributed data repository; controlling, by the networking hardware device having the first type, network traffic based on the identity awareness data.