Server Port Security via Policy Server and PorTender

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security systems, particularly server firewalls, rely solely on administrator passwords for security, which is inadequate given the vulnerability of internet-connected networks to unauthorized access.

Innovation Solution

Implementing a policy server and port-tending agent (PorTender) that regulate IP port access, manage security policies, and provide multifactor authentication, along with dynamic access leases and emergency policies to enhance security and manage connectivity settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only administrator password is used for security, then the system is simple to operate, but the security reliability is insufficient

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into multiple independent authentication factors: password authentication, IP address verification, and digital signature validation. Each factor operates as a separate module that can be independently configured and managed, allowing the system to achieve high security reliability without becoming unmanageably complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from single-dimensional password-based security to multi-dimensional security by adding spatial (IP address) and cryptographic (digital signature) dimensions. This dimensional expansion allows the system to achieve superior security reliability while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multifactor authentication and dynamic access leases are implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Access leases are pre-configured with defined duration and permissions before being granted to users. The system prepares access policies, IP address ranges, and digital signature requirements in advance, allowing multifactor authentication to operate smoothly without real-time complexity. This preliminary preparation enables high security reliability while keeping the active system state manageable.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamic access control where security parameters such as IP addresses, port access permissions, and lease durations can be modified during operation without requiring complete system reconfiguration. This dynamic capability allows the system to adapt to changing security requirements while maintaining operational simplicity through centralized policy management.

Inventive Principle:
Principle #15Dynamics

3Reliability

If port access is strictly regulated by policy server, then security reliability is enhanced, but ease of operation is reduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The policy server automatically performs IP address verification, digital signature validation, and access lease management without requiring manual intervention for each authentication event. The system serves itself by autonomously enforcing security policies, checking credentials, and managing port access permissions, thereby maintaining high security reliability while preserving ease of operation through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9531754B2Methods, circuits, apparatus, systems and associated software applications for providing security on one or more servers, including virtual servers
Publication Date: 2016.12.27 CHECK POINT SOFTWARE TECH LTD
  • US9531754B2 patent drawing
  • US9531754B2 patent drawing
  • US9531754B2 patent drawing

AI summary

Disclosed are methods, circuits, apparatus, systems and associated software applications for providing security on one or more servers, including virtual servers. A server operating system may include or be otherwise functionally associated with a firewall application, which firewall application may regulate IP port access to resources on the server. A port-tending agent or application (PorTender) running on the server, or on a functionally associated computing platform, may monitor and regulate server port status (e.g. opened, closed, and conditionally opened). The PorTender may initiate and engage in communication sessions with a policy server, from which policy server the PorTender may receive port, user and security policies and/or settings.