Proxy-Based Firewall Port Control via Cryptographic Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network firewall ports in datacenters with multiple physical and virtual computing systems is complex, as it involves manual, time-consuming, and error-prone processes, leading to security concerns due to open ports and potential interruptions from premature closure of necessary ports.

Innovation Solution

Implementing a proxy system that intercepts client requests, authenticates clients using digital certificates, and dynamically manages network ports by communicating with a port management service to open and close ports only as needed, ensuring secure and efficient communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual port management is used, then security control is maintained, but time consumption and error rate increase

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automatic port management where the proxy server autonomously opens and closes ports based on client authentication status and service requirements, eliminating manual intervention while maintaining security control through automated authorization verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of port opening/closing is replaced with an automated electronic system that uses digital certificates, cryptographic authentication, and programmatic port management to achieve the same security objectives faster and with fewer errors

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If ports are kept open, then network traffic flow is ensured, but security risk increases

Engineering Contradiction:
Improvenetwork traffic flowVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts port states from closed to open based on real-time authentication results and service requirements, then automatically closes them when no longer needed. This dynamic port management ensures traffic flow when authorized while maintaining security by closing ports when authentication fails or services end

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The proxy server continuously monitors authentication status and service state, using this feedback to automatically open ports when authorized clients need access and close ports when authentication expires or services terminate, creating a self-regulating security mechanism

Inventive Principle:
Principle #23Feedback

3Reliability

If static firewall rules are implemented, then security policy is enforced, but adaptability to changing network needs decreases

Engineering Contradiction:
Improvesecurity policyVSAvoidadaptability to changing needs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system replaces static firewall rules with dynamic port management that automatically adapts to changing network needs based on real-time authentication results, service requirements, and client authorization status, while maintaining security policy through programmed authorization verification

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes port state parameters dynamically based on authentication status, service type, and authorization level, allowing the firewall to adapt its behavior to different scenarios while maintaining security through controlled parameter changes based on authorization policies

Inventive Principle:
Principle #35Parameter changes

4Productivity

If automated port management is implemented, then time consumption is reduced, but system complexity increases

Engineering Contradiction:
Improveport management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The proxy server acts as an intermediary component that handles the complexity of automated authentication and port management, shielding the simplicity of the original firewall while enabling advanced features. This intermediary absorbs the complexity of certificate validation, authorization verification, and automated port control

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10454899B1Controlling firewall ports in virtualized environments through public key cryptography
Publication Date: 2019.10.22 AMAZON TECH INC
  • US10454899B1 patent drawing
  • US10454899B1 patent drawing
  • US10454899B1 patent drawing

AI summary

A system and method for client authentication wherein a client computing system is authenticated by at least performing, at an authentication system different than a target computing system, a set of validation operations on authorization information addressed to a destination port of the target computing system, and, as a result of the client computing system being authenticated by the set of validation operations, switching to a mode wherein a port of the target computing system is opened and data from the client computing system is communicated to the port of the target computing system.