Reliable Firewall Spanning Multiple Routers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in reliably synchronizing firewall session state information across multiple routers, leading to potential disruptions and inefficiencies in firewall policy management and session handling.

Innovation Solution

The implementation of a system that supports the communication of firewall session state information between primary and secondary routers via secure datapath and control plane sessions, using encrypted links to establish a logically extended datapath, enabling rapid propagation of session state information and minimizing session disruptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall session state information is synchronized across multiple routers, then reliability and high availability are improved, but system complexity and synchronization overhead increase

Engineering Contradiction:
Improvefirewall session availabilityVSAvoidsynchronization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the firewall session state synchronization into separate independent paths: a control plane path for managing session state information and a datapath for forwarding traffic. This segmentation allows each path to be optimized independently, reducing overall system complexity while maintaining reliability through distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a control plane as an intermediary layer that manages firewall session state information between routers. This intermediary handles the complexity of synchronization, authentication, and state management, allowing the datapath to remain simple and focused on high-speed packet forwarding without burden of complex synchronization logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If session state information is propagated rapidly across routers, then session disruption is minimized, but network latency and processing overhead increase

Engineering Contradiction:
Improvesession continuityVSAvoidinformation propagation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The control plane pre-establishes secure sessions and synchronizes firewall session state information before traffic needs to be forwarded. By preparing the synchronization path and authentication credentials in advance, the system minimizes disruption when actual traffic flow occurs, as the state information is already available at both endpoints.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous synchronization of firewall session state information between control plane and datapath, ensuring that session state is always up-to-date without interrupting traffic flow. This continuous action allows rapid propagation of state changes while maintaining session continuity, as the synchronization operates in parallel with data forwarding.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If secure encrypted links are established between routers, then security and reliability are improved, but processing overhead and computational requirements increase

Engineering Contradiction:
Improvesecure communicationVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the cryptographic processing requirements from the high-speed datapath and concentrates them in the control plane. This extraction allows the datapath to focus on simple packet forwarding with minimal processing, while the control plane handles the computationally intensive encryption and decryption operations for secure session establishment and maintenance.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11483287B2Reliable firewall
Publication Date: 2022.10.25 NOKIA SOLUTIONS & NETWORKS OY
  • US11483287B2 patent drawing
  • US11483287B2 patent drawing
  • US11483287B2 patent drawing

AI summary

Various example embodiments of a reliable firewall are presented herein. Various example embodiments of a reliable firewall may be configured to provide a single, stateful firewall spanning multiple routers. Various example embodiments of a reliable firewall spanning multiple routers may be configured to provide a reliable firewall configured to protect high-availability network services, network services using multipath routing, or the like, as well as various combinations thereof. Various example embodiments of a reliable firewall spanning multiple routers may be configured to provide a reliable firewall by supporting synchronization of firewall synchronization information (e.g., firewall policy information, firewall session state information, or the like, as well as various combinations thereof) across the multiple routers.