Multilayer Access Control Security System with Automated Policy Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are inefficient due to the lack of coordinated protection across multiple layers, requiring independent setup and programming of security devices, leading to vulnerabilities and increased complexity for network administrators.

Innovation Solution

A multilayer access control security system that automates the generation and application of access policy rules across various network layers, reducing the need for multiple rule generation mechanisms and allowing for coordinated filtering to enhance security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security systems are placed at multiple levels or layers within the network, then more than one level of protection is provided, but the system becomes expensive and inefficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple security functions (firewall, intrusion detection, intrusion prevention, proxy server) into a single integrated security appliance. This consolidation allows the system to provide multiple levels of protection while reducing the number of separate devices, thereby lowering costs and improving operational efficiency through unified management and coordinated security responses.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated security appliance performs multiple security functions simultaneously - acting as a firewall for network traffic filtering, intrusion detection system for threat identification, intrusion prevention system for attack blocking, and proxy server for application-level proxying. This multi-functionality eliminates the need for separate dedicated devices for each security layer, reducing overall system complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate security systems are placed at multiple levels or layers within the network, then more than one level of protection is provided, but the setup and programming becomes complex and time-consuming

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By merging multiple security systems into a single integrated appliance, the patent eliminates the complexity of configuring and coordinating multiple separate devices. The unified system provides consistent security policies across all layers without requiring administrators to manually synchronize settings between different security devices, significantly simplifying setup and programming.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated security appliance includes automated features such as automatic intrusion detection response, coordinated filtering across layers, and built-in security updates. These self-service capabilities reduce the manual configuration and programming time required to maintain effective security across multiple network layers.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If traffic flows through multiple protection systems independently, then each system can be optimized for its specific function, but coordination between systems is lost resulting in inefficiencies

Engineering Contradiction:
Improvefunction optimizationVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges multiple security processing functions into a single coordinated system where traffic flows through integrated firewall filtering, intrusion detection, intrusion prevention, and proxy services in a unified manner. This coordination allows the system to optimize for each specific function while maintaining overall efficiency through shared resources and synchronized decision-making across all security layers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated security appliance implements feedback mechanisms where intrusion detection systems can trigger prevention actions, and processing results at one layer can influence decisions at subsequent layers. This coordinated feedback loop eliminates inefficiencies by ensuring all security systems work together seamlessly rather than independently, improving overall processing efficiency while maintaining functional optimization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7900240B2Multilayer access control security system
Publication Date: 2011.03.01 CITRIX SYSTEMS INC
  • US7900240B2 patent drawing
  • US7900240B2 patent drawing
  • US7900240B2 patent drawing

AI summary

A computer-based system provides secure, configurable access to computer network resources. A human-readable language is provided for defining access policy rules. Rules in this language are converted in an automated fashion into filters applied within the various subsystems and components in a multi-layer security system. Network users are authenticated by an access control security system that obtains basic information about that user. Based on the user ID, a set of abstract policies can be retrieved. The retrieved policies are associated with the user and the groups associated with that user. Based on the retrieved rules, a set of rules for multiple layers of the network are generated and applied to those subsystems. Two or more of the subsystems may be placed in series with different types of processing occurring in each of the subsystems, reducing the workload of subsequent subsystems.