Multi-Channel Firewall Control for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls in computer systems are vulnerable to IP spoofing attacks and port closure issues due to the need to keep ports open for legitimate network communications, especially in cloud-computing systems, where network activities extend beyond traditional client-server communications, and current solutions do not effectively manage port durations and security.
Innovation Solution
The implementation of multiple communication channels and networks to negotiate data transfers through firewalls, using an ad hoc network to exchange security information and control the opening and closing of firewall ports, with on-the-fly encryption and an end-of-transfer message to manage port durations securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewall ports are kept open for legitimate network communications, then network communication reliability is improved, but vulnerability to IP spoofing attacks increases
Solution Approach 1:
The system performs preliminary authentication and security verification through the first communication channel before opening the firewall port. Security information including authentication credentials is exchanged in advance, and the port is only opened after verification is complete, preventing unauthorized access while allowing legitimate communications
Solution Approach 2:
The patent introduces a multi-channel communication system where a first communication channel serves as an intermediary for security negotiations. This separate channel acts as a mediator that handles authentication and security information exchange, isolating the control plane from the data plane and preventing direct attack vectors through the data channel
2Adaptability or versatility
If firewall ports are opened for cloud-computing network activities, then adaptability to modern network protocols is improved, but port management complexity increases
Solution Approach 1:
The system dynamically opens and closes firewall ports based on real-time communication needs. Ports are opened only when legitimate communications are detected through the first channel and closed automatically when communications end, transforming static port management into a dynamic, demand-driven process that adapts to cloud-computing workloads
Solution Approach 2:
The patent segments network communication into two distinct channels: a first communication channel for security negotiations and control, and a second communication channel for actual data transfer. This segmentation separates management functions from data functions, simplifying port management by dedicating specific ports to specific purposes
3Productivity
If firewall ports remain open longer for extended network activities, then productivity of network operations is improved, but exposure to security attacks increases
Solution Approach 1:
The system implements periodic port opening and closing cycles synchronized with communication sessions. Ports are opened periodically when needed for data transfer and closed periodically when not in use, creating a rhythm of accessibility that balances productivity needs with security requirements by limiting exposure windows
Data Source
AI summary
A method for controlling the transfer of data through a firewall. The method includes one or more computer processors establishing a first communication channel between a first server and a second server. The method further includes transmitting, via the first communication channel, information related to a pending transmission of data from the first server to the second server. The method further includes receiving from the second server, via the first communication channel, a set of security information associated with accessing the second server via a second communication channel. The method further includes establishing the second communication channel between the first server and the second server based on the set of security information received from the second server. The method further includes transmitting the data from the first server to the second server utilizing the established second communication channel.


