Multi-Channel Firewall Control for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in computer systems are vulnerable to IP spoofing attacks and port closure issues due to the need to keep ports open for legitimate network communications, especially in cloud-computing systems, where network activities extend beyond traditional client-server communications, and current solutions do not effectively manage port durations and security.

Innovation Solution

The implementation of multiple communication channels and networks to negotiate data transfers through firewalls, using an ad hoc network to exchange security information and control the opening and closing of firewall ports, with on-the-fly encryption and an end-of-transfer message to manage port durations securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall ports are kept open for legitimate network communications, then network communication reliability is improved, but vulnerability to IP spoofing attacks increases

Engineering Contradiction:
Improvenetwork communication reliabilityVSAvoidvulnerability to IP spoofing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and security verification through the first communication channel before opening the firewall port. Security information including authentication credentials is exchanged in advance, and the port is only opened after verification is complete, preventing unauthorized access while allowing legitimate communications

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a multi-channel communication system where a first communication channel serves as an intermediary for security negotiations. This separate channel acts as a mediator that handles authentication and security information exchange, isolating the control plane from the data plane and preventing direct attack vectors through the data channel

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If firewall ports are opened for cloud-computing network activities, then adaptability to modern network protocols is improved, but port management complexity increases

Engineering Contradiction:
Improveadaptability to modern network protocolsVSAvoidport management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically opens and closes firewall ports based on real-time communication needs. Ports are opened only when legitimate communications are detected through the first channel and closed automatically when communications end, transforming static port management into a dynamic, demand-driven process that adapts to cloud-computing workloads

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments network communication into two distinct channels: a first communication channel for security negotiations and control, and a second communication channel for actual data transfer. This segmentation separates management functions from data functions, simplifying port management by dedicating specific ports to specific purposes

Inventive Principle:
Principle #1Segmentation

3Productivity

If firewall ports remain open longer for extended network activities, then productivity of network operations is improved, but exposure to security attacks increases

Engineering Contradiction:
Improveproductivity of network operationsVSAvoidexposure to security attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements periodic port opening and closing cycles synchronized with communication sessions. Ports are opened periodically when needed for data transfer and closed periodically when not in use, creating a rhythm of accessibility that balances productivity needs with security requirements by limiting exposure windows

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11277381B2Multi-channel based just-in-time firewall control
Publication Date: 2022.03.15 KYNDRYL INC
  • US11277381B2 patent drawing
  • US11277381B2 patent drawing
  • US11277381B2 patent drawing

AI summary

A method for controlling the transfer of data through a firewall. The method includes one or more computer processors establishing a first communication channel between a first server and a second server. The method further includes transmitting, via the first communication channel, information related to a pending transmission of data from the first server to the second server. The method further includes receiving from the second server, via the first communication channel, a set of security information associated with accessing the second server via a second communication channel. The method further includes establishing the second communication channel between the first server and the second server based on the set of security information received from the second server. The method further includes transmitting the data from the first server to the second server utilizing the established second communication channel.