Interconnected Firewall Security Between Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls are typically implemented at the periphery of networks, leaving network devices such as routers and switches unprotected, allowing security threats to proliferate throughout the network.

Innovation Solution

A security device is interconnected via multiple links between multiple network devices, implementing a firewall security policy to protect against network-based security threats by receiving and processing data units according to the policy, while maintaining transparent data transmission and preserving network topology through the use of virtual wires.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls are implemented at the periphery of the network, then the local system is protected from Internet-based attacks, but network devices such as routers and switches remain vulnerable to security threats

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network security protection into multiple segments by deploying firewalls not only at the periphery but also at intermediate network devices (routers, switches). This segmentation allows security protection to be distributed throughout the network hierarchy, ensuring that both peripheral systems and internal network devices are protected against security threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends security protection from a single-dimensional peripheral placement to a multi-dimensional distribution throughout the network. By implementing firewalls at multiple levels (peripheral firewalls and intermediate firewalls), the security architecture moves from protecting only the edge to protecting the entire network path, including intermediate devices.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If firewalls are deployed throughout the network at multiple locations, then security coverage is improved, but network complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the firewall mechanism universal by implementing it across different types of network devices (routers, switches, and other intermediate devices). This multi-functional approach allows the same security mechanism to be applied consistently throughout the network, improving security coverage while using standardized implementations to manage complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces intermediate firewalls as mediator devices between network segments. These intermediate firewalls act as security gates that control traffic flow between different network parts, providing centralized security management and reducing the complexity of securing distributed network environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls are inserted between network devices, then security protection is imposed at diverse locations, but data transmission path length increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata transmission path
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent applies local quality by implementing firewalls at specific strategic locations (between network devices) rather than uniformly throughout the entire network. This allows security protection to be concentrated where most needed while minimizing the impact on overall data transmission paths.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables data units to skip intermediate firewall inspections by implementing efficient routing mechanisms that allow traffic to bypass security checks when the path is already authenticated, thus reducing unnecessary path length extensions while maintaining security.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS8261337B1Firewall security between network devices
Publication Date: 2012.09.04 JUNIPER NETWORKS INC
  • US8261337B1 patent drawing
  • US8261337B1 patent drawing
  • US8261337B1 patent drawing

AI summary

A security device may be interconnected, via multiple links, between multiple network devices in a network. The firewall device may include multiple input interfaces that receive data units from a first network device destined for a second network device of the multiple network devices, identify a session associated with each of the data units, and process the data units in accordance with the identified sessions and a security policy.