Identity-Based Firewall Policy Evaluation for Dynamic Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IP-based firewall solutions struggle to enforce policy requirements in dynamic environments where IP addresses continuously change, leading to inaccurate trusted status determinations and potential security vulnerabilities.

Innovation Solution

The implementation of an identity-based firewall policy evaluation method that intercepts packets, determines the sender entity's permitted communications based on unique entity identifiers and firewall policies, and performs mitigation actions when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP-based firewall solutions are used to enforce policy rules, then existing solutions can scan incoming packets to identify IP addresses, but they fail in dynamic environments where IP addresses continuously change, leading to inaccurate trusted status determination

Engineering Contradiction:
Improvetrusted status determination accuracyVSAvoidadaptability to dynamic IP address changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the identification parameter from IP address to application identity. Instead of relying on network layer IP addresses that change dynamically, the system uses application-layer identity information that remains stable and uniquely identifies the application regardless of IP changes. This parameter change resolves the contradiction by making trusted status determination accurate (improving reliability) while adapting to dynamic IP environments (improving adaptability).

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an identity-based firewall as an intermediary layer between network traffic and policy enforcement. This intermediary extracts and uses application identity information from packets to determine trusted status, rather than relying directly on IP addresses. The intermediary approach allows the system to maintain accurate trusted status determination while being transparent to IP address changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If IP-based solutions are used for policy enforcement, then they can check IP addresses of communicating applications, but they cannot function properly when load balancers are utilized due to continuous IP mapping changes

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidcompatibility with load balancer environments
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system changes the policy enforcement parameter from IP address to application identity. By extracting identity information at the application layer, the firewall can enforce policies based on who the application is rather than where it is located (IP address). This enables proper policy enforcement (improving ease of operation) while being compatible with load balancer environments that dynamically change IP mappings (improving adaptability).

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent moves policy enforcement from the network layer (IP address dimension) to the application layer (identity dimension). This dimensional shift allows the system to enforce policies based on application identity that persists across different IP addresses and load balancer configurations, resolving the contradiction between policy enforcement capability and load balancer compatibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If entity identifiers are used instead of IP addresses, then accurate trusted status determination is achieved in dynamic environments, but the system complexity increases due to identity management requirements

Engineering Contradiction:
Improvetrusted status determination accuracyVSAvoididentity management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the identity-based approach universal by having applications explicitly provide their identity information as part of the communication protocol. This universal identity provision mechanism allows the system to achieve accurate trusted status determination (improving reliability) while keeping the firewall implementation relatively simple, as it only needs to extract and compare identity information without managing complex identity databases.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If application-to-application identity firewall policies are implemented, then secure communication rules are enforced, but the evaluation process requires intercepting and analyzing packets which may impact communication performance

Engineering Contradiction:
Improvesecurity enforcement accuracyVSAvoidcommunication throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having applications provide their identity information in advance as part of the packet header or initial communication protocol. The firewall extracts this pre-provided identity information efficiently without needing to deeply inspect packet contents or perform complex analysis, thus maintaining security enforcement accuracy (improving reliability) while minimizing impact on communication throughput (improving productivity).

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12224982B2Distributed identity-based firewall policy evaluation
Publication Date: 2025.02.11 PALO ALTO NETWORKS INC
  • US12224982B2 patent drawing
  • US12224982B2 patent drawing
  • US12224982B2 patent drawing

AI summary

Methods and systems for identity-based firewall policy evaluation and for encoding entity identifiers for use in identity-based firewall policy evaluation. A packet from a sender entity to a recipient entity is intercepted. A determination is made whether the sender entity is permitted to communicate with the recipient entity according to a firewall policy, wherein the firewall policy indicates a plurality of entity identifiers, and each entity identifier is unique among the plurality of entity identifiers. Rules for communications among the plurality of entities include a list of pairs of entities which are permitted to communicate with each other. The packet is forwarded to the recipient entity when it is determined that the sender entity is permitted to communicate with the recipient entity. At least one mitigation action is performed when it is determined that the recipient entity is not permitted to communicate with the sender entity.