Deriving Outbound Security Policies from Inbound Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring firewalls and IPsec tools to ensure consistent security policies is complex and prone to errors, leading to vulnerabilities in data security, particularly due to the complexity of IPsec terminology and the need for symmetric outbound and inbound security policies.

Innovation Solution

A security system that automatically derives an outbound security policy from an inbound security policy, using a user interface to define security rules that generate consistent firewall and connection rules, ensuring matching inbound and outbound security suites for computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security personnel manually configure firewall rules and IPsec rules separately, then they can implement security policies, but the configuration process becomes complex and error-prone due to the need for coordination between overlapping technologies

Engineering Contradiction:
Improvesecurity policy implementationVSAvoidconfiguration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines firewall rule configuration and IPsec rule configuration into a single integrated security policy definition process. Instead of requiring security personnel to separately configure and coordinate two different rule sets, the system allows them to define a unified security policy that automatically generates both firewall and IPsec rules, eliminating the complexity of manual coordination between overlapping technologies.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary component that acts as a translator between high-level security policy definitions and the specific syntax requirements of firewall and IPsec configurations. This intermediary automatically handles the complex task of converting a single security policy into coordinated firewall and IPsec rules, reducing errors and simplifying the configuration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If security personnel manually coordinate firewall rules and IPsec rules, then they can ensure consistency, but the process becomes tedious and time-consuming due to the complexity of IPsec terminology and multiple decisions required

Engineering Contradiction:
Improveconsistency of security policiesVSAvoidconfiguration time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining security policy templates and rules that automatically generate both firewall and IPsec configurations. Instead of requiring security personnel to manually coordinate every detail of both rule sets, the system has already prepared the coordinated rules in advance, reducing the time and effort required for configuration while maintaining consistency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying mechanisms where a single security policy definition is automatically replicated and adapted into both firewall rule format and IPsec rule format. This copying process ensures consistency between the two rule sets while eliminating the need for manual coordination, significantly reducing configuration time and effort.

Inventive Principle:
Principle #26Copying

3Reliability

If IPsec tools are configured to implement security policies, then data transmission security can be ensured, but the process is difficult due to confusing and inconsistent IPsec terminology and the need for many decisions

Engineering Contradiction:
Improvedata transmission securityVSAvoidIPsec configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer that shields security personnel from the complexity of IPsec terminology and configuration details. This intermediary automatically handles the translation from high-level security policy definitions to specific IPsec rule syntax, eliminating the need for security personnel to navigate confusing and inconsistent IPsec terminology while ensuring proper data transmission security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables the IPsec configuration process to serve itself by automatically generating IPsec rules from security policy definitions without requiring manual intervention for each configuration decision. The system self-adjusts to handle the complexity of IPsec terminology and makes the necessary configuration decisions automatically, significantly improving ease of operation while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

4Stability of the object's composition

If outbound security policy is manually configured to be symmetric with inbound security policy, then matching security suites can be achieved, but the process becomes tedious and complex

Engineering Contradiction:
Improvesymmetry of security policiesVSAvoidsecurity policy configuration
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent applies asymmetry in reverse by allowing asymmetric configuration inputs (different inbound and outbound security requirements) to automatically generate symmetric security policies. Instead of requiring security personnel to manually ensure symmetry between inbound and outbound policies, the system accepts asymmetric definitions and automatically balances them, reducing configuration complexity while maintaining the necessary symmetry for matching security suites.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS7581241B2Generating an outbound connection security policy based on an inbound connections security policy
Publication Date: 2009.08.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7581241B2 patent drawing
  • US7581241B2 patent drawing
  • US7581241B2 patent drawing

AI summary

A security system that allows an outbound security policy for the connection security to be automatically derived from an inbound security policy for connection security is provided. The security system for an inbound security policy has security suites that each specify one or more security algorithms. Because the security system offers an outbound security suite that matches an inbound security suite, the computing devices that have the same inbound security policy have matching inbound and outbound security suites.