Home Router Firewall Automation with Neural Network Device Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall configurations for home networks are complex and difficult for average users to manage, requiring specific IP and port configurations to control Internet access, which is not suitable for home applications where devices of different types need varying access rules based on time and day.

Innovation Solution

A user-friendly firewall system integrated into a home router that automatically identifies devices using pattern recognition and neural networks to apply predefined templates for different device types, allowing users to set access rules without manual configuration of IP addresses or ports, enabling easy management of firewall operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If business level firewall devices are used to block access to particular Internet sites, then network access control is improved, but device complexity increases making it difficult for average users to configure

Engineering Contradiction:
Improvenetwork access controlVSAvoidfirewall configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically discovers devices on the network and assigns them to device types based on their network behavior and characteristics. Users simply need to select a device type from a list, and the system automatically generates and applies the appropriate firewall rules, eliminating the need for manual configuration of ports and IP addresses.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary layer between the user and the complex firewall configuration. This intermediary automatically translates simple user selections (device types) into complex firewall rules, acting as a mediator that simplifies the user interface while maintaining comprehensive control capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If parental monitoring applications are installed on individual devices, then Internet access control for specific devices is improved, but control effectiveness deteriorates when devices are used by other users

Engineering Contradiction:
Improvedevice-specific access controlVSAvoidmulti-user control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The firewall system is implemented at the router level, making it universal for all devices and users on the network. A single firewall configuration can simultaneously apply different rules to different device types regardless of which user is operating which device, providing both device-specific and user-specific control capabilities from a centralized location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent moves the control mechanism from the device dimension (individual applications on each device) to the network dimension (centralized router-level control). This dimensional shift allows simultaneous management of multiple devices and users from a single point, enabling comprehensive multi-user control that individual device applications cannot achieve.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If manual configuration of IP addresses and ports is required for firewall rules, then access control precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidfirewall rule configuration
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs automatic device discovery and classification, generating precise firewall rules without requiring manual input of IP addresses or ports. The system services itself by automatically monitoring network traffic, identifying devices, and configuring appropriate rules based on device type, maintaining precision while eliminating manual configuration efforts.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary device discovery and classification before firewall rules are needed. By pre-identifying devices and their types, the system has all necessary information ready to generate precise firewall rules automatically when required, eliminating the need for users to perform manual configuration tasks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11916882B2Methods and apparatus for controlling and implementing firewalls
Publication Date: 2024.02.27 CHARTER COMM OPERATING LLC
  • US11916882B2 patent drawing
  • US11916882B2 patent drawing
  • US11916882B2 patent drawing

AI summary

Network traffic through a router, e.g., home router, operating as a firewall is monitored and analyzed the network to identify devices and the type of one or more of the identified devices. In some embodiments, the device type identification is performed using a neural network. The router stores a set of firewall templates. At different times, different templates are applied, e.g. based on mode of operation, user selection, and/or time information. Rules in a firewall template, applicable at a given time to traffic corresponding to identified devices, that are attempting to send or receive via the router, are applied. Different rules may, and sometimes do, apply to different device type classifications.