Network Access Control Unit Dynamic Address Filter Rule Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for configuring firewalls in communication networks are limited by the requirement for static communication network addresses, which becomes impractical with dynamically changing or decentralized IPv6 addresses, as they cannot efficiently update message filter rules to adapt to these changes.

Innovation Solution

A method where a network access control unit, such as a firewall, registers communication devices with their addresses and device descriptions in an address management unit, allowing for the update of message filter rules by replacing the communication network address of one device with that of another with an identical device description, using a converter unit to maintain consistent filter rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall configuration methods are used with static addresses, then message filter rules can be configured, but they cannot adapt to dynamically changing or decentralized IPv6 addresses

Engineering Contradiction:
Improveadaptability to dynamic addressesVSAvoidcomplexity of address management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an address management unit as an intermediary between communication devices and the network access control unit. This unit maintains the mapping between device descriptions and dynamic IPv6 addresses, enabling the firewall to filter traffic based on device descriptions rather than directly managing dynamic addresses. The intermediary absorbs the complexity of address management while preserving the simplicity of rule-based filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy of the address management functionality within the network access control unit. The control unit maintains a local copy of the device description to address mapping, allowing it to independently update message filter rules when address changes occur, without requiring manual reconfiguration or complex address tracking.

Inventive Principle:
Principle #26Copying

2Productivity

If message filter rules are manually updated for each address change, then accurate filtering is maintained, but the system cannot handle dynamic address changes efficiently

Engineering Contradiction:
Improveefficiency of rule updatingVSAvoidtime for address management
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The address management unit continuously monitors address assignments and provides feedback to the network access control unit. When a device's IPv6 address changes, the address management unit detects this change and automatically triggers an update of the message filter rules, eliminating manual intervention and reducing the time required for address management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes the mapping between device descriptions and addresses in the address management unit before address changes occur. This preliminary organization of address information enables rapid rule updates when changes happen, as the control unit can quickly retrieve the new address mapping without performing complex address management tasks during the update process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If firewalls are configured with device-specific rules, then precise control is achieved, but the complexity increases with each new device

Engineering Contradiction:
Improvereliability of data flow controlVSAvoidcomplexity of filter rule management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network access control unit is designed with universal functionality to handle diverse communication devices through a unified approach. Instead of creating device-specific configuration procedures, the unit uses a single mechanism that works with any device by matching packet source addresses against the stored device description to address mapping, thereby maintaining reliability while reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the filtering parameter from direct address matching to device description-based matching. By storing and comparing device descriptions rather than hardcoding rules for each device, the system maintains precise control over data flow while reducing the complexity of filter rule management, as device descriptions provide a standardized interface for identifying communication devices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10341249B2Method for updating message filter rules of a network access control unit of an industrial communication network address management unit, and converter unit
Publication Date: 2019.07.02 SIEMENS AG
  • US10341249B2 patent drawing

AI summary

Method and system of updating message filter rules of a network access control unit of an industrial communication network. At least one address-based message filter rule is assigned to the first communication device. The first communication device is replaced with the second communication device, and the second communication device is registered in the address management unit in response to the replacement of the first communication device with the second communication device. Upon determining that a communication device with an identical communication device description is already registered, the address management unit transmits a change message to the network access control unit or to the converter unit. The communication network address of the first communication device is replaced with the communication network address of the second communication device based on the at least one address-based message filter rule.