Presence-Based Firewall Pinhole Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack the ability to automatically configure firewalls or access points to allow remote access to private networks, making it difficult for users to access network resources from external locations while maintaining security and consistency of network configurations.

Innovation Solution

A method and system that utilize presence information to manage network access by updating presence information for end users and automatically configuring access points to allow communications through firewalls, enabling pinhole configurations to follow users across endpoints, ensuring secure and consistent access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual firewall configuration is used to allow remote access, then security control is maintained, but ease of operation deteriorates due to complex manual configuration steps

Engineering Contradiction:
Improveease of remote access configurationVSAvoidcomplexity of firewall configuration process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables self-service automatic configuration of firewall pinholes through presence information. When a user logs into a network endpoint, the access point automatically detects the presence information and configures the necessary pinholes without requiring manual intervention, thus improving ease of operation while maintaining security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration actions by pre-establishing presence information templates and access rules before remote access is needed. When a user needs remote access, the system already has the necessary configuration patterns ready to automatically apply, eliminating complex manual configuration steps

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic pinhole configuration is implemented, then ease of operation improves, but reliability worsens due to potential security vulnerabilities

Engineering Contradiction:
Improveautomation of access configurationVSAvoidsecurity of network access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the access point continuously monitors presence information and automatically adjusts pinhole configurations based on detected user presence. This closed-loop approach ensures that automatic configuration only occurs when proper presence information is verified, maintaining security while enabling automation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces presence information as an intermediary layer between the automatic configuration mechanism and the firewall pinholes. This intermediary validates and mediates the configuration process, ensuring that automatic pinhole creation follows predefined security policies and only occurs when appropriate presence conditions are met

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If presence information is maintained and updated, then adaptability improves for remote access, but device complexity increases due to presence management requirements

Engineering Contradiction:
Improveadaptability to remote access scenariosVSAvoidcomplexity of presence information management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements universal presence information structures that serve multiple functions: user identification, location tracking, and access authorization. This multi-functional approach allows the same presence information to be used across different remote access scenarios and network endpoints, improving adaptability without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs dynamic presence information that automatically updates as users move between endpoints or change access states. This dynamic approach allows the network to automatically adapt to changing remote access scenarios without requiring complex manual reconfiguration, as the presence information continuously reflects current user states

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8079062B2Method and system using presence information to manage network access
Publication Date: 2011.12.13 CISCO TECHNOLOGY INC
  • US8079062B2 patent drawing
  • US8079062B2 patent drawing
  • US8079062B2 patent drawing

AI summary

In accordance with a particular embodiment of the present invention, a method using presence information to manage network access includes maintaining presence information for an end user. When a remote access request is received from the end user at a remote endpoint, the presence information for the end user is updated to identify the presence of the end user at one or more network endpoints associated with a private network. An access point to the private network is then automatically configured to allow any communications addressed to an IP address associated with the one or more network endpoints to pass through the access point.