Personalized Firewall Property Server Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall configurations are inflexible and require extensive reconfiguration when security requirements change, especially in multi-user environments where IP addresses are dynamic, leading to significant administrative overhead and limitations in personalized security settings.

Innovation Solution

Introducing a method that uses property values associated with data packets to match rules in a firewall, allowing organizations to define their own properties and rules based on security policies, with a property server providing authorization levels and service agreements, enabling flexible and dynamic updates without reconfiguring the entire firewall.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall rule bases are used with fixed IP address filtering, then firewall configuration is simple and straightforward, but the system lacks flexibility when security requirements change or IP addresses are dynamic

Engineering Contradiction:
Improveflexibility of firewall configurationVSAvoidcomplexity of firewall rule base
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall rule base into two distinct parts: traditional filtering rules and property value associations. The filtering rules remain simple and unchanged, while the property values store the dynamic security requirements. This segmentation allows the system to be flexible without complicating the rule base structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces property values as an intermediary layer between the static filtering rules and dynamic security requirements. Instead of modifying rules to accommodate changing requirements, the system uses property values associated with identification values (like IP addresses) to store flexible security attributes, which are then evaluated during packet filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the entire firewall configuration is updated when security requirements change, then centralized control is maintained, but administrative overhead increases significantly

Engineering Contradiction:
Improvecentralized configuration controlVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the dynamic security requirements from the main firewall configuration and stores them separately as property values. When security requirements change, only the specific property values need to be updated, not the entire firewall configuration. This extraction reduces administrative overhead while maintaining centralized control through the property value management system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces dynamic property values that can be individually updated without reconfiguring the entire firewall. The system allows selective modification of property values associated with specific identification values, enabling dynamic adaptation to changing security requirements while maintaining overall configuration stability.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If IP address-based filtering is used in dynamic IP environments, then configuration is straightforward, but personalized security settings for different users cannot be implemented

Engineering Contradiction:
Improvesimplicity of configurationVSAvoidpersonalization capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by associating specific property values with specific identification values (such as IP addresses). Each user or device can have its own customized property values that reflect their specific security requirements, while the overall filtering rules remain general and applicable to all. This allows personalized security settings without complicating the global configuration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8099776B2Personalized firewall
Publication Date: 2012.01.17 FORCEPOINT LLC
  • US8099776B2 patent drawing
  • US8099776B2 patent drawing
  • US8099776B2 patent drawing

AI summary

A personalized firewall or other network gateway is provided by a method of matching a data packet to a rule in a network gateway having a rule base. One or more identification values are determined based on the data packet and property value(s) associated with said one or more identification values are queried and received from a property server. The property value(s) describe for example allowed connections and services for an entity associated with the identification value(s). The property value(s) are compared to at least one rule in the rule base, said at least one rule comprising property value(s) and an action, and the action defined in said at least one rule is taken, if said property value(s) of the rule match corresponding property value(s) associated with said one or more identification values.