Zone-Based Multicast Firewall Pre-Post Replication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls face difficulties in applying security services to multicast traffic, either applying services uniformly before replication, leading to inadequate security, or after replication, resulting in unscalable solutions, especially in high-end environments, and often break down multicast into unicast flows, wasting resources.

Innovation Solution

An integrated zone-based firewall within a routing device that allows pre- and post-replication security services to be applied to multicast packets, leveraging multiple planes of the network device for efficient replication and scaling, with a user interface for defining zone-based policies and services, and cooperation between routing and services daemons to create service-aware outgoing interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security services are applied before replication of multicast traffic, then uniform treatment of all multicast traffic is achieved, but security richness and effectiveness deteriorate

Engineering Contradiction:
Improveuniform treatmentVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments multicast traffic handling into distinct phases: pre-replication security services applied to the original multicast packet, and post-replication security services applied to individual replicated copies. This segmentation allows different security treatments for different recipients while maintaining operational simplicity through automated phase-based processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary security services before replication to establish baseline security measures on the original multicast packet. This preliminary action ensures that critical security checks are performed once on the source packet, improving efficiency while maintaining security effectiveness.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security services are applied after replication of multicast traffic, then individual security treatment for each recipient is achieved, but scalability deteriorates in high-volume environments

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides security service application into two segments: pre-replication services that process the original packet once, and post-replication services that process individual copies. This segmentation reduces overall processing load by avoiding redundant pre-replication security operations on each packet copy, thereby improving scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial security services selectively - not all security services are applied to every packet copy. Instead, certain services are applied only once before replication, while others are applied after replication based on recipient-specific requirements. This partial action approach reduces computational overhead and improves scalability.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multicast traffic is broken down into unicast flows for security service application, then individual security treatment is achieved, but resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity treatment precisionVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges the handling of multicast traffic by maintaining it as a unified flow through the pre-replication security service stage, rather than splitting it into separate unicast flows. This merging approach allows shared processing resources to handle multiple recipients simultaneously, improving resource efficiency while still enabling individualized post-replication security treatment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal pre-replication security processing stage that serves all multicast recipients simultaneously. This multi-functional stage handles security checks for multiple destination groups in parallel, reducing overall resource consumption compared to treating each recipient as a separate unicast flow.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9191366B2Scalable security services for multicast in a router having integrated zone-based firewall
Publication Date: 2015.11.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9191366B2 patent drawing
  • US9191366B2 patent drawing
  • US9191366B2 patent drawing

AI summary

A multicast-capable firewall allows firewall security policies to be applied to multicast traffic. The multicast-capable firewall may be integrated within a routing device, thus allowing a single device to provide both routing functionality, including multicast support, as well as firewall services. The routing device provides a user interface by which a user specifies one or more zones to be recognized by the integrated firewall when applying stateful firewall services to multicast packets. The user interface supports a syntax that allows the user to define subsets of the plurality of interfaces associated with the zones, and define a single multicast policy to be applied to multicast sessions associated with a multicast group. The multicast policy identifies common services to be applied pre-replication, and exceptions specifying additional services to be applied post-replication to copies of the multicast packets for the one or more zones.