Identity-Based Firewall Filtering in Identity-Oriented Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional IP network firewalls are inadequate in securely filtering data packets, as they rely on IP addresses which can be easily spoofed, leading to vulnerabilities in protecting receiving host entities from attackers.
Innovation Solution
Implementing identity-based and metadata-based firewalls within an Identity-Oriented Network (IEN) that utilize a distributed mapping system to manage identifiers and locators, allowing firewalls to determine whether to forward or discard data packets based on policies associated with the identities and metadata of sending and receiving host entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IP-based firewalls are used to filter data packets, then network traffic can be controlled, but security is compromised because IP addresses can be easily spoofed
Solution Approach 1:
The patent changes the fundamental parameter used for firewall filtering from IP addresses to identity-based identifiers. This parameter change makes spoofing ineffective because identities are cryptographically bound to host entities and cannot be easily falsified, thereby improving security while maintaining traffic control capabilities
Solution Approach 2:
The patent introduces an identity-based identifier system as an intermediary between the sender and receiver. This intermediary layer provides verifiable identity information that cannot be spoofed, allowing firewalls to make secure filtering decisions without directly trusting the source IP address
2Reliability
If firewalls filter data packets at the destination, then security policies can be enforced, but network resources are wasted transmitting malicious packets
Solution Approach 1:
The patent enables firewalls to perform security filtering in advance, closer to the source of data packets, by using identity-based identifiers. This preliminary action allows malicious packets to be blocked before consuming significant network resources, while still enforcing security policies at the destination
3Reliability
If identity-based firewalls are implemented, then security against spoofing is improved, but system complexity increases due to distributed mapping systems
Solution Approach 1:
The patent creates a universal identity-based identifier system that serves multiple functions: authentication, authorization, and firewall filtering. This multi-functional approach consolidates what would otherwise require separate complex systems, reducing overall system complexity while maintaining strong anti-spoofing capabilities
Data Source
AI summary
A method implemented by a firewall device in a network, comprising storing, by a memory, a firewall policy comprising information indicating whether to forward a data packet from a sending host entity to a receiving host entity, receiving, by a receiver, a data packet from a sending host entity, wherein the data packet includes an identifier of the receiving host entity, and determining, by a processor coupled to the memory and the receiver, whether to forward the data packet to the receiving host entity based on the firewall policy and the identifier of the receiving host entity.


