Passport-Controlled Firewall Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firewall management in corporate IP networks and Cloud computing environments requires human intervention for adding and resetting firewall rules, leading to delays and increased costs due to limited authorized personnel and frequent changes in IP addresses.

Innovation Solution

A method and system for dynamically modifying firewall rules using a 'unit of deployment' that includes application code and a signed passport, where the passport contains a firewall rule and hash values, allowing automated and secure modification of firewall settings without human intervention, with a heart-beat time-out mechanism for automatic rule resetting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If human intervention is required for adding and resetting firewall rules, then security control is maintained, but delays and increased costs occur due to limited authorized personnel

Engineering Contradiction:
Improvefirewall rule modification speedVSAvoidfirewall management system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables automated self-service firewall rule management where the deployment system automatically adds and removes firewall rules without requiring manual intervention from authorized personnel. The passport mechanism allows the system to autonomously handle firewall configuration changes, eliminating delays caused by limited human resources while maintaining security through automated authentication and validation processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-validating the application code hash against the passport before allowing firewall rule modifications. This preliminary verification ensures that only authorized applications can trigger firewall changes, enabling automated rule management while maintaining security controls without requiring continuous human oversight

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If firewall rules are modified frequently in Cloud computing environments, then adaptability is improved, but costs increase due to frequent changes in IP addresses

Engineering Contradiction:
Improvefirewall rule adaptabilityVSAvoidtime for firewall rule changes
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements dynamic firewall rule management where rules are automatically added and removed based on real-time deployment events. The passport mechanism enables flexible, time-limited firewall rules that adapt to changing IP addresses and deployment configurations in Cloud environments, allowing frequent changes without manual intervention and reducing the time required for each change

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback mechanisms where the deployment system automatically provides updated passport information containing new IP addresses and configuration details. This feedback loop enables the firewall system to automatically adapt to changes in Cloud computing environments, maintaining adaptability while reducing the time and effort required for frequent reconfiguration

Inventive Principle:
Principle #23Feedback

3Productivity

If automated firewall rule modification is implemented, then productivity is improved, but security risks increase without proper authentication

Engineering Contradiction:
Improveautomated firewall rule modificationVSAvoidsecurity of firewall rule changes
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces the passport as an intermediary mechanism that mediates between the deployment system and the firewall configuration. The passport contains authenticated information about the application code and authorized firewall rules, serving as a secure intermediary that enables automated rule modifications while maintaining reliability through cryptographic authentication and validation processes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and validation actions by comparing the hash of the application code against the passport before allowing any firewall rule modifications. This preliminary security check ensures that only authorized applications can trigger automated firewall changes, maintaining security reliability while enabling improved productivity through automation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10637829B2Passport-controlled firewall
Publication Date: 2020.04.28 KYNDRYL INC
  • US10637829B2 patent drawing
  • US10637829B2 patent drawing
  • US10637829B2 patent drawing

AI summary

A method and system for dynamically modifying rules in a firewall infrastructure. A signed passport is encrypted based on a public key certificate registered with a trusted signer. The signed passport includes a hash value that includes a heart-beat time-out interval and a firewall rule. A trigger signal within the heart-beat time-out interval is generated. The signed passport and the trigger signal are transmitted within the heart-beat time-out interval to a border control agent of a firewall in the firewall infrastructure. In response to receiving, from the border control agent, a continuous confirmation of the firewall rule within a time interval shorter than the heart-beat time-out interval, the firewall is modified according to the firewall rule. In response to determining that the trigger signal was not received by the border control agent within the heart-beat time-out interval, the firewall rule is reset.