Centralized Star Network for Dynamic Firewall Rule Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions, such as VPNs, face challenges in managing access rights and security policies across distributed private networks, particularly in ensuring secure communication over insecure networks like the Internet, and in handling complex firewall rule settings across geographically distant locations.

Innovation Solution

A star-connected network architecture where a central server node establishes encrypted connections with client nodes using SSL sessions, routing all communications through a firewall that enforces security policies and updates rules dynamically based on established connections, with tamper-resistant hardware modules for authentication and a security policy engine to manage access and detect potential attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional VPN solutions are used to extend private networks over the Internet, then remote users can access the private network, but security control becomes difficult as users typically get full access once they negotiate the firewall

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The firewall rules are made dynamic by automatically updating them based on established encrypted connections. The system transitions from static security rules to dynamic rules that adapt in real-time based on connection status, allowing granular control over which clients can communicate with which resources while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the firewall continuously monitors established encrypted connections and automatically adjusts its rules accordingly. This closed-loop control ensures that security policies are enforced consistently based on actual connection states, preventing unauthorized access while allowing legitimate communications.

Inventive Principle:
Principle #23Feedback

2Reliability

If distributed private networks use leased lines to couple geographically distant LANs, then network connectivity is established, but the cost increases and coordinated firewall rule setting becomes complex

Engineering Contradiction:
Improvenetwork connectivityVSAvoidfirewall rule coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The central server acts as an intermediary that manages all encrypted connections between clients. Instead of requiring direct peer-to-peer connections that would need coordinated firewall rules at each site, all communications are routed through the central server which automatically manages the connection rules, simplifying firewall configuration to a single centralized point.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The central server performs multiple functions including establishing encrypted connections, managing authentication, routing packets, and dynamically updating firewall rules. This multi-functional approach consolidates what would otherwise require separate systems at each distributed location into a single universal platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple firewalls are deployed at each distributed site, then local security requirements can be met, but the complexity of coordinating and maintaining consistent firewall rules across all sites increases

Engineering Contradiction:
Improvelocal security enforcementVSAvoidfirewall rule management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The complex firewall rule management functionality is extracted from distributed locations and consolidated into the central server. Each client device only needs simple local firewall rules to communicate with the server, while the complex inter-client communication rules are automatically managed by the central server, dramatically simplifying operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2090073B1Secure network architecture
Publication Date: 2010.11.03 BRITISH TELECOM PLC
  • EP2090073B1 patent drawingFigure 1
  • EP2090073B1 patent drawingFigure 2
  • EP2090073B1 patent drawingFigure 3

AI summary

The present invention provides a star-connected network (C1-C4, P1-P8) having a number of peripheral nodes (P1-P8) and a central control arrangement (C1-C4). Each peripheral node has means for restricting communications across the network to the central control arrangement using a respective encrypted connection unless the peripheral node has received explicit authorisation from the control arrangement to set up a direct connection with another peripheral node. The central control arrangement comprises: means for establishing an encrypted connection with each peripheral node; means for exchanging control packets with two or more peripheral nodes using two or more respective encrypted connections in order to set up an authorised connection between two peripheral nodes; a database storing security policy information specifying what connections between peripheral nodes are allowable; and authorisation means for authorising connections which are allowable according to the stored security policy information using the control packet exchanging means.