Identity-Based Firewall Filtering in Identity-Oriented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IP network firewalls are inadequate in securely filtering data packets, as they rely on IP addresses which can be easily spoofed, leading to vulnerabilities in protecting receiving host entities from attackers.

Innovation Solution

Implementing identity-based and metadata-based firewalls within an Identity-Oriented Network (IEN) that utilize a distributed mapping system to manage identifiers and locators, allowing firewalls to determine whether to forward or discard data packets based on policies associated with the identities and metadata of sending and receiving host entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IP-based firewalls are used to filter data packets, then network traffic can be controlled, but security is compromised because IP addresses can be easily spoofed

Engineering Contradiction:
ImprovesecurityVSAvoidspoofing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the fundamental parameter used for firewall filtering from IP addresses to identity-based identifiers. This parameter change makes spoofing ineffective because identities are cryptographically bound to host entities and cannot be easily falsified, thereby improving security while maintaining traffic control capabilities

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an identity-based identifier system as an intermediary between the sender and receiver. This intermediary layer provides verifiable identity information that cannot be spoofed, allowing firewalls to make secure filtering decisions without directly trusting the source IP address

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls filter data packets at the destination, then security policies can be enforced, but network resources are wasted transmitting malicious packets

Engineering Contradiction:
Improveprotection effectivenessVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables firewalls to perform security filtering in advance, closer to the source of data packets, by using identity-based identifiers. This preliminary action allows malicious packets to be blocked before consuming significant network resources, while still enforcing security policies at the destination

Inventive Principle:
Principle #10Preliminary action

3Reliability

If identity-based firewalls are implemented, then security against spoofing is improved, but system complexity increases due to distributed mapping systems

Engineering Contradiction:
Improveanti-spoofing capabilityVSAvoiddistributed mapping system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal identity-based identifier system that serves multiple functions: authentication, authorization, and firewall filtering. This multi-functional approach consolidates what would otherwise require separate complex systems, reducing overall system complexity while maintaining strong anti-spoofing capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10958623B2Identity and metadata based firewalls in identity enabled networks
Publication Date: 2021.03.23 FUTUREWEI TECHNOLOGIES INC
  • US10958623B2 patent drawing
  • US10958623B2 patent drawing
  • US10958623B2 patent drawing

AI summary

A method implemented by a firewall device in a network, comprising storing, by a memory, a firewall policy comprising information indicating whether to forward a data packet from a sending host entity to a receiving host entity, receiving, by a receiver, a data packet from a sending host entity, wherein the data packet includes an identifier of the receiving host entity, and determining, by a processor coupled to the memory and the receiver, whether to forward the data packet to the receiving host entity based on the firewall policy and the identifier of the receiving host entity.