Network Access Policy Protocol for Home Router Firewall Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing home network firewalls require manual configuration and often necessitate a separate appliance, complicating access control policy management and communication between the home network and service providers.

Innovation Solution

A network access policy protocol (APP) that communicates access control policies using the same protocol across existing firewalls, with capabilities to propagate policies automatically and reduce unwanted traffic by utilizing OSPF for policy exchange and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate firewall appliance is deployed in the home network, then access control policy management is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveaccess control policy managementVSAvoidfirewall configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the firewall functionality with the existing router by implementing a unified access control mechanism. The router's routing table is integrated with access control lists (ACLs), allowing the same device to perform both routing and firewall functions. This eliminates the need for a separate firewall appliance while maintaining access control capabilities through a consolidated system that manages policies centrally.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The router is designed to perform multiple functions: it serves as both the routing device and the firewall. The routing table is enhanced to include access control information, enabling the router to make routing decisions based on both path optimization and security policies. This multi-functional approach allows a single device to handle both network connectivity and access control without requiring additional specialized hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual firewall configuration is used, then access control policies can be implemented, but configuration time and administrative overhead increase

Engineering Contradiction:
Improveaccess control policy implementationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automatic configuration of access control policies by allowing the router to autonomously populate ACL entries based on routing information. The routing protocol automatically exchanges access control lists between routers, eliminating the need for manual configuration of firewall rules. Policies are automatically applied when routing changes occur, reducing administrative overhead and configuration time while maintaining reliable access control implementation.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If different protocols are used for firewall communication, then existing firewall compatibility is maintained, but protocol complexity and interoperability issues arise

Engineering Contradiction:
Improvefirewall compatibilityVSAvoidcommunication protocol
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses a universal routing protocol (such as OSPF) that serves dual purposes: it handles both routing information exchange and access control policy distribution. The same protocol mechanisms are employed for both functions, eliminating the need for separate communication protocols between firewalls and routers. This approach maintains compatibility with existing routing infrastructure while simplifying the overall communication protocol by consolidating multiple functions into a single unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9621554B2Method for propagating access policies
Publication Date: 2017.04.11 CISCO TECHNOLOGY INC
  • US9621554B2 patent drawing
  • US9621554B2 patent drawing
  • US9621554B2 patent drawing

AI summary

The present disclosure describes a network appliance and associated access policy protocol (APP) that communicates and obeys access policies within a network. The network appliance (APP node) propagates access policies to other APP nodes that can utilize the policies most effectively. When an access policy reaches the network boundary, intra network bandwidth is optimized. The access policies may be distributed and executed in the cloud—e.g. proxy firewall, proxy policy execution.