Interconnected Firewall Security Between Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewalls are typically implemented at the periphery of networks, leaving network devices such as routers and switches unprotected, allowing security threats to proliferate throughout the network.
Innovation Solution
A security device is interconnected via multiple links between multiple network devices, implementing a firewall security policy to protect against network-based security threats by receiving and processing data units according to the policy, while maintaining transparent data transmission and preserving network topology through the use of virtual wires.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are implemented at the periphery of the network, then the local system is protected from Internet-based attacks, but network devices such as routers and switches remain vulnerable to security threats
Solution Approach 1:
The patent divides the network security protection into multiple segments by deploying firewalls not only at the periphery but also at intermediate network devices (routers, switches). This segmentation allows security protection to be distributed throughout the network hierarchy, ensuring that both peripheral systems and internal network devices are protected against security threats.
Solution Approach 2:
The patent extends security protection from a single-dimensional peripheral placement to a multi-dimensional distribution throughout the network. By implementing firewalls at multiple levels (peripheral firewalls and intermediate firewalls), the security architecture moves from protecting only the edge to protecting the entire network path, including intermediate devices.
2Reliability
If firewalls are deployed throughout the network at multiple locations, then security coverage is improved, but network complexity increases
Solution Approach 1:
The patent makes the firewall mechanism universal by implementing it across different types of network devices (routers, switches, and other intermediate devices). This multi-functional approach allows the same security mechanism to be applied consistently throughout the network, improving security coverage while using standardized implementations to manage complexity.
Solution Approach 2:
The patent introduces intermediate firewalls as mediator devices between network segments. These intermediate firewalls act as security gates that control traffic flow between different network parts, providing centralized security management and reducing the complexity of securing distributed network environments.
3Reliability
If firewalls are inserted between network devices, then security protection is imposed at diverse locations, but data transmission path length increases
Solution Approach 1:
The patent applies local quality by implementing firewalls at specific strategic locations (between network devices) rather than uniformly throughout the entire network. This allows security protection to be concentrated where most needed while minimizing the impact on overall data transmission paths.
Solution Approach 2:
The patent enables data units to skip intermediate firewall inspections by implementing efficient routing mechanisms that allow traffic to bypass security checks when the path is already authenticated, thus reducing unnecessary path length extensions while maintaining security.
Data Source
AI summary
A security device may be interconnected, via multiple links, between multiple network devices in a network. The firewall device may include multiple input interfaces that receive data units from a first network device destined for a second network device of the multiple network devices, identify a session associated with each of the data units, and process the data units in accordance with the identified sessions and a security policy.


