Identity-Based Distributed Cloud Firewall for Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Firewall as a Service (FWaaS) technologies often result in decreased network performance, increased latency, and limited flexibility in customizing security rules and policies, making them vulnerable to security breaches and unable to meet specific organizational needs.

Innovation Solution

A cloud-based FWaaS solution that employs a core security service for authentication, connecting user devices to a private cloud with segmented firewall rules, allowing granular access control and prioritization of firewall rules, and integrating with features like Deep Packet Inspection and DNS Filtering for comprehensive protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FWaaS is used, then cloud-based security is provided, but network performance decreases and latency increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the firewall service into distributed firewall instances deployed across multiple cloud locations, allowing traffic to be filtered locally rather than routing all traffic through a centralized FWaaS provider. This segmentation maintains security functionality while reducing network latency and improving performance by eliminating unnecessary traffic routing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces local firewall agents as intermediaries between network traffic and the cloud-based management console. These agents handle local filtering decisions, reducing the performance impact by keeping critical filtering operations local while maintaining centralized policy management for security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional FWaaS is used, then centralized security management is provided, but flexibility in customizing security rules is limited

Engineering Contradiction:
Improvecentralized managementVSAvoidcustomization flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that can be customized for different organizational units, departments, or user groups while maintaining centralized management. The system allows flexible configuration of security rules that adapt to specific organizational needs without requiring centralized reconfiguration, enabling both ease of operation and customization flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables local customization of security rules at distributed firewall instances while maintaining centralized policy templates. Each location can tailor security configurations to local requirements while benefiting from centralized management capabilities, achieving both ease of operation and adaptability.

Inventive Principle:
Principle #3Local quality

3Reliability

If centralized FWaaS infrastructure is used, then security filtering is provided, but vulnerability to security breaches increases

Engineering Contradiction:
Improvesecurity filteringVSAvoidvulnerability to breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security filtering across multiple distributed locations rather than relying on a single centralized FWaaS infrastructure. This segmentation reduces the attack surface and limits the impact of potential breaches to local segments, maintaining security filtering effectiveness while reducing overall vulnerability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts critical security filtering functionality from the centralized cloud infrastructure and places it locally at distributed firewall instances. This extraction reduces dependency on the centralized infrastructure, maintaining security filtering while reducing vulnerability to breaches of the central system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12010099B1Identity-based distributed cloud firewall for access and network segmentation
Publication Date: 2024.06.11 720 IT UAB
  • US12010099B1 patent drawing
  • US12010099B1 patent drawing
  • US12010099B1 patent drawing

AI summary

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.