Perimeter Gateway Application Whitelist for Secure Node Flow
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems are ineffective in securely exchanging data anywhere, anytime, and struggle to identify and control devices like mobile and IoT devices within networks, leading to vulnerabilities due to unauthorized access and malicious data transmission through encrypted tunnels.
Innovation Solution
The implementation of a network security system that establishes a defined perimeter with an application whitelist, allowing only authorized applications to connect and transmit trusted data, creating secure node and application flows to prevent malicious data from entering secure networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a device connects to a private network via a tunnel (VPN), then network security is enhanced, but the device may still transmit malicious data to secure devices in the private network
Solution Approach 1:
The patent segments the network connection into multiple controlled node flows, where each flow is independently authorized and monitored. Instead of treating the entire tunnel as a single secure channel, the system divides it into discrete flows that can be individually controlled and inspected, preventing malicious data from compromising the entire connection.
Solution Approach 2:
The patent introduces an intermediary security system that acts as a mediator between the public network and private network. This intermediary monitors and controls data transmission, inspecting packets and enforcing security policies to block malicious data while allowing legitimate communication through authorized applications.
2Adaptability or versatility
If multiple applications execute on a device, then functionality is improved, but vulnerability to malicious data increases
Solution Approach 1:
The patent applies local quality by assigning different security attributes to different applications and their corresponding node flows. Each application's data transmission is evaluated and controlled independently based on its specific security requirements and authorization status, rather than applying a uniform security policy to all applications.
Solution Approach 2:
The patent changes security parameters dynamically based on application behavior and data characteristics. The system monitors application performance and data patterns, adjusting security controls in real-time to block malicious data while maintaining functionality for authorized applications.
3Reliability
If a tunnel is used for data transmission, then network security is improved, but unauthorized access to secure data may still occur
Solution Approach 1:
The patent implements preliminary action by establishing security controls and authorization checks before data transmission begins. The system pre-authores applications and configures security policies for each node flow, ensuring that unauthorized access attempts are blocked before they can compromise secure data.
Data Source
AI summary
The disclosed embodiments relate to securely transferring data between a source node and a destination node using an application whitelist. A control flow may be established between a source node and a perimeter gateway. the perimeter controller may receive a request to establish a node flow between an application executing on the source node and the destination node. the perimeter controller may determine whether the first application is included in an application whitelist that includes applications allowed to transfer data to nodes in a private network via a node flow. A node flow between the source node and destination node may be established upon determining that the first application is included in the application whitelist to facilitate secure data transfer between the source node and destination node.


