Subscriber-Based Firewall Policy Enforcement Against Unauthorized Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall technologies fail to effectively prevent unauthorized access to secure networks by relying solely on IP addresses, leading to potential security breaches.

Innovation Solution

Implementing a method and system that enforce firewall and security policies based on subscriber identification and class, using a network security manager apparatus to identify unique subscriber numbers and classes, and apply corresponding network security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP address-based firewall rules are used, then network access control is implemented, but unauthorized access cannot be completely prevented

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the identification parameter from IP address to device identifier (such as MAC address, device hash, or other unique device characteristics). This parameter change enables more precise device identification and allows the firewall to distinguish between different devices using the same IP address, thereby preventing unauthorized access while maintaining network access control functionality

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary component (firewall appliance or software module) that sits between the network traffic and the destination, performing device identification and policy enforcement. This intermediary translates device characteristics into enforceable security policies, bridging the gap between physical device properties and logical access control rules

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If subscriber identification-based security policies are implemented, then unauthorized access is prevented, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the firewall system to perform multiple functions: device identification, subscriber classification, policy enforcement, and security monitoring. By consolidating these functions into a single multi-functional system, the patent reduces overall network infrastructure complexity while maintaining enhanced security capabilities through subscriber identification

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the security policy enforcement into distinct layers: device identification layer, subscriber classification layer, and policy enforcement layer. This segmentation allows each component to be independently configured and managed, reducing system complexity while enabling sophisticated security policies based on subscriber identification

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12489731B1Methods for enforcing firewall and security policies based on subscriber identification and devices thereof
Publication Date: 2025.12.02 F5 NETWORKS INC
  • US12489731B1 patent drawing
  • US12489731B1 patent drawing
  • US12489731B1 patent drawing

AI summary

Methods, non-transitory computer readable media, and network security manager apparatus that assists with enforcing firewall and security policies based on subscriber identification and subscriber class includes receiving network traffic from a plurality of client devices. A unique subscriber identification number and a subscriber class for each of the plurality of client devices is identified. One or more network security policies associated with each of the identified unique subscriber identification number and the subscriber class is obtained. Each of the obtained one or more network security policies is enforced on the corresponding plurality of client devices or a network security manager apparatus.