Smart Firewall Filtering in Label-Based Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall devices are limited in implementing policies for packets traversing specific paths through a network, as they typically rely on source, destination, and traffic class, failing to account for more complex routing requirements such as traversing particular sequences of network nodes.

Innovation Solution

A network device communicates with a path computation element to receive label sets that define specific sequences of nodes, allowing it to configure firewall policies based on these labels and perform actions on packets accordingly, enabling more sophisticated routing decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firewall devices use traditional filtering methods based on source, destination, and traffic class, then the firewall implementation is simple, but the ability to control packets based on specific path sequences is lost

Engineering Contradiction:
Improvefirewall policy control capabilityVSAvoidfirewall implementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a path computation element as an intermediary that computes label sets representing specific path sequences through the network. This intermediary enables the firewall device to control packets based on node sequences without the firewall device itself needing to perform complex path computations, thus resolving the contradiction between enhanced adaptability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the filtering parameters from traditional source/destination/traffic class to label sets that encode path sequences. By transforming the control parameters, the firewall device gains the ability to control packets based on specific node sequences while maintaining a relatively simple filtering mechanism.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If firewall devices implement complex path-based filtering, then packet routing control is improved, but processing overhead increases

Engineering Contradiction:
Improvepacket routing control accuracyVSAvoidfirewall device processing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The path computation element performs path computation and label set generation in advance, before packets need to be filtered. By pre-computing the label sets that represent desired path sequences, the system avoids performing complex computations in real-time during packet processing, thus improving routing control accuracy while reducing processing overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the complex path computation function from the firewall device and places it in a separate path computation element. This separation allows the firewall device to focus on simple label matching operations while the complex computation is performed elsewhere, reducing processing overhead while maintaining reliable path-based filtering.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If traditional firewalls are used, then device simplicity is maintained, but the ability to avoid specific network segments is lost

Engineering Contradiction:
Improvenetwork segment avoidance capabilityVSAvoidfirewall configuration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The path computation element acts as an intermediary that translates high-level path requirements (such as avoiding specific network segments) into concrete label sets. This intermediary enables the firewall device to achieve complex network segment avoidance capabilities while the configuration process remains relatively simple, as users only need to specify their path requirements rather than manually constructing label sets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12003483B1Smart firewall filtering in a label-based network
Publication Date: 2024.06.04 JUNIPER NETWORKS INC
  • US12003483B1 patent drawing
  • US12003483B1 patent drawing
  • US12003483B1 patent drawing

AI summary

A network device may receive an input identifying one or more conditions associated with traversal of packets through a network and one or more actions to be performed if the one or more conditions are satisfied. The network device may transmit, to a path computation element, a request for a label set that satisfies the one or more conditions. The network device may receive the label set from the path computation element. The network device may configure a firewall policy indicating that the one or more actions are to be performed for a packet associated with a label stack that includes the label set.