Network Access Control Unit Dynamic Address Filter Rule Update
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for configuring firewalls in communication networks are limited by the requirement for static communication network addresses, which becomes impractical with dynamically changing or decentralized IPv6 addresses, as they cannot efficiently update message filter rules to adapt to these changes.
Innovation Solution
A method where a network access control unit, such as a firewall, registers communication devices with their addresses and device descriptions in an address management unit, allowing for the update of message filter rules by replacing the communication network address of one device with that of another with an identical device description, using a converter unit to maintain consistent filter rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall configuration methods are used with static addresses, then message filter rules can be configured, but they cannot adapt to dynamically changing or decentralized IPv6 addresses
Solution Approach 1:
The patent introduces an address management unit as an intermediary between communication devices and the network access control unit. This unit maintains the mapping between device descriptions and dynamic IPv6 addresses, enabling the firewall to filter traffic based on device descriptions rather than directly managing dynamic addresses. The intermediary absorbs the complexity of address management while preserving the simplicity of rule-based filtering.
Solution Approach 2:
The system creates a virtual copy of the address management functionality within the network access control unit. The control unit maintains a local copy of the device description to address mapping, allowing it to independently update message filter rules when address changes occur, without requiring manual reconfiguration or complex address tracking.
2Productivity
If message filter rules are manually updated for each address change, then accurate filtering is maintained, but the system cannot handle dynamic address changes efficiently
Solution Approach 1:
The address management unit continuously monitors address assignments and provides feedback to the network access control unit. When a device's IPv6 address changes, the address management unit detects this change and automatically triggers an update of the message filter rules, eliminating manual intervention and reducing the time required for address management.
Solution Approach 2:
The system pre-establishes the mapping between device descriptions and addresses in the address management unit before address changes occur. This preliminary organization of address information enables rapid rule updates when changes happen, as the control unit can quickly retrieve the new address mapping without performing complex address management tasks during the update process.
3Reliability
If firewalls are configured with device-specific rules, then precise control is achieved, but the complexity increases with each new device
Solution Approach 1:
The network access control unit is designed with universal functionality to handle diverse communication devices through a unified approach. Instead of creating device-specific configuration procedures, the unit uses a single mechanism that works with any device by matching packet source addresses against the stored device description to address mapping, thereby maintaining reliability while reducing overall system complexity.
Solution Approach 2:
The system changes the filtering parameter from direct address matching to device description-based matching. By storing and comparing device descriptions rather than hardcoding rules for each device, the system maintains precise control over data flow while reducing the complexity of filter rule management, as device descriptions provide a standardized interface for identifying communication devices.
Data Source
AI summary
Method and system of updating message filter rules of a network access control unit of an industrial communication network. At least one address-based message filter rule is assigned to the first communication device. The first communication device is replaced with the second communication device, and the second communication device is registered in the address management unit in response to the replacement of the first communication device with the second communication device. Upon determining that a communication device with an identical communication device description is already registered, the address management unit transmits a change message to the network access control unit or to the converter unit. The communication network address of the first communication device is replaced with the communication network address of the second communication device based on the at least one address-based message filter rule.
