Identity-Based Firewall Policy Evaluation for Dynamic Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IP-based firewall solutions struggle to enforce policy requirements in dynamic environments where IP addresses continuously change, leading to inaccurate trusted status determinations and potential security vulnerabilities.
Innovation Solution
The implementation of an identity-based firewall policy evaluation method that intercepts packets, determines the sender entity's permitted communications based on unique entity identifiers and firewall policies, and performs mitigation actions when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP-based firewall solutions are used to enforce policy rules, then existing solutions can scan incoming packets to identify IP addresses, but they fail in dynamic environments where IP addresses continuously change, leading to inaccurate trusted status determination
Solution Approach 1:
The patent changes the identification parameter from IP address to application identity. Instead of relying on network layer IP addresses that change dynamically, the system uses application-layer identity information that remains stable and uniquely identifies the application regardless of IP changes. This parameter change resolves the contradiction by making trusted status determination accurate (improving reliability) while adapting to dynamic IP environments (improving adaptability).
Solution Approach 2:
The patent introduces an identity-based firewall as an intermediary layer between network traffic and policy enforcement. This intermediary extracts and uses application identity information from packets to determine trusted status, rather than relying directly on IP addresses. The intermediary approach allows the system to maintain accurate trusted status determination while being transparent to IP address changes.
2Ease of operation
If IP-based solutions are used for policy enforcement, then they can check IP addresses of communicating applications, but they cannot function properly when load balancers are utilized due to continuous IP mapping changes
Solution Approach 1:
The system changes the policy enforcement parameter from IP address to application identity. By extracting identity information at the application layer, the firewall can enforce policies based on who the application is rather than where it is located (IP address). This enables proper policy enforcement (improving ease of operation) while being compatible with load balancer environments that dynamically change IP mappings (improving adaptability).
Solution Approach 2:
The patent moves policy enforcement from the network layer (IP address dimension) to the application layer (identity dimension). This dimensional shift allows the system to enforce policies based on application identity that persists across different IP addresses and load balancer configurations, resolving the contradiction between policy enforcement capability and load balancer compatibility.
3Reliability
If entity identifiers are used instead of IP addresses, then accurate trusted status determination is achieved in dynamic environments, but the system complexity increases due to identity management requirements
Solution Approach 1:
The patent makes the identity-based approach universal by having applications explicitly provide their identity information as part of the communication protocol. This universal identity provision mechanism allows the system to achieve accurate trusted status determination (improving reliability) while keeping the firewall implementation relatively simple, as it only needs to extract and compare identity information without managing complex identity databases.
4Reliability
If application-to-application identity firewall policies are implemented, then secure communication rules are enforced, but the evaluation process requires intercepting and analyzing packets which may impact communication performance
Solution Approach 1:
The patent applies preliminary action by having applications provide their identity information in advance as part of the packet header or initial communication protocol. The firewall extracts this pre-provided identity information efficiently without needing to deeply inspect packet contents or perform complex analysis, thus maintaining security enforcement accuracy (improving reliability) while minimizing impact on communication throughput (improving productivity).
Data Source
AI summary
Methods and systems for identity-based firewall policy evaluation and for encoding entity identifiers for use in identity-based firewall policy evaluation. A packet from a sender entity to a recipient entity is intercepted. A determination is made whether the sender entity is permitted to communicate with the recipient entity according to a firewall policy, wherein the firewall policy indicates a plurality of entity identifiers, and each entity identifier is unique among the plurality of entity identifiers. Rules for communications among the plurality of entities include a list of pairs of entities which are permitted to communicate with each other. The packet is forwarded to the recipient entity when it is determined that the sender entity is permitted to communicate with the recipient entity. At least one mitigation action is performed when it is determined that the recipient entity is not permitted to communicate with the sender entity.


