Personalized Firewall Property Server Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall configurations are inflexible and require extensive reconfiguration when security requirements change, especially in multi-user environments where IP addresses are dynamic, leading to significant administrative overhead and limitations in personalized security settings.
Innovation Solution
Introducing a method that uses property values associated with data packets to match rules in a firewall, allowing organizations to define their own properties and rules based on security policies, with a property server providing authorization levels and service agreements, enabling flexible and dynamic updates without reconfiguring the entire firewall.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall rule bases are used with fixed IP address filtering, then firewall configuration is simple and straightforward, but the system lacks flexibility when security requirements change or IP addresses are dynamic
Solution Approach 1:
The patent segments the firewall rule base into two distinct parts: traditional filtering rules and property value associations. The filtering rules remain simple and unchanged, while the property values store the dynamic security requirements. This segmentation allows the system to be flexible without complicating the rule base structure.
Solution Approach 2:
The patent introduces property values as an intermediary layer between the static filtering rules and dynamic security requirements. Instead of modifying rules to accommodate changing requirements, the system uses property values associated with identification values (like IP addresses) to store flexible security attributes, which are then evaluated during packet filtering.
2Reliability
If the entire firewall configuration is updated when security requirements change, then centralized control is maintained, but administrative overhead increases significantly
Solution Approach 1:
The patent extracts the dynamic security requirements from the main firewall configuration and stores them separately as property values. When security requirements change, only the specific property values need to be updated, not the entire firewall configuration. This extraction reduces administrative overhead while maintaining centralized control through the property value management system.
Solution Approach 2:
The patent introduces dynamic property values that can be individually updated without reconfiguring the entire firewall. The system allows selective modification of property values associated with specific identification values, enabling dynamic adaptation to changing security requirements while maintaining overall configuration stability.
3Ease of operation
If IP address-based filtering is used in dynamic IP environments, then configuration is straightforward, but personalized security settings for different users cannot be implemented
Solution Approach 1:
The patent applies local quality by associating specific property values with specific identification values (such as IP addresses). Each user or device can have its own customized property values that reflect their specific security requirements, while the overall filtering rules remain general and applicable to all. This allows personalized security settings without complicating the global configuration.
Data Source
AI summary
A personalized firewall or other network gateway is provided by a method of matching a data packet to a rule in a network gateway having a rule base. One or more identification values are determined based on the data packet and property value(s) associated with said one or more identification values are queried and received from a property server. The property value(s) describe for example allowed connections and services for an entity associated with the identification value(s). The property value(s) are compared to at least one rule in the rule base, said at least one rule comprising property value(s) and an action, and the action defined in said at least one rule is taken, if said property value(s) of the rule match corresponding property value(s) associated with said one or more identification values.


