Temporary Firewall Rules for Secure Remote Access to Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing access to networked electronic devices are vulnerable to attacks through exposed ports, particularly when users have dynamic IP addresses and cannot use VPN software, leading to unauthorized access and lateral movement within internal networks.

Innovation Solution

Implementing a network security system that requires two-factor authentication, using a mobile device-generated verification code, to dynamically create one-time port forwarding or firewall rules for authorized users, ensuring secure remote access without exposing ports to attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional port forwarding rules are used to enable remote access, then accessibility is improved, but security is worsened due to exposed ports vulnerable to attacks

Engineering Contradiction:
Improveremote access capabilityVSAvoidexposed ports vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic port forwarding rules that are automatically created and deleted based on authentication status and connection state. The firewall rule dynamically opens a port for the duration of an authorized session and then closes it, transforming the static security model into a dynamic one that adapts to user actions and time limits.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication actions before allowing any network access. Users must authenticate through a portal and have their credentials verified against domain controllers or other authentication systems before any port forwarding rules are created, ensuring that access is granted only after thorough verification.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If static firewall rules are configured for permanent access, then accessibility is improved, but adaptability is worsened when users have dynamic IP addresses

Engineering Contradiction:
Improveconsistent accessVSAvoiddynamic IP compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system dynamically generates firewall rules based on the user's current IP address at the time of authentication. When a user authenticates, the system creates a port forwarding rule that includes the user's current IP address as the external address, automatically adapting to IP changes without requiring manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication portal provides feedback to users about their authentication status and the temporary nature of their access. The system monitors connection states and automatically adjusts firewall rules based on real-time information about active sessions, IP addresses, and authentication validity.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple authentication factors are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication portal serves as an intermediary layer between users and the network resources. It centralizes the authentication logic, handling multiple authentication factors (username/password, certificates, biometrics) and coordinating with domain controllers and other authentication systems without requiring complex client-side software on user devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication portal is designed as a universal authentication service that can handle multiple authentication methods and integrate with various authentication systems. It provides a single access point for diverse authentication requirements, making the system adaptable to different security needs without requiring separate specialized solutions for each factor.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250373583A1Securing access to network devices utilizing authentication and dynamically generated temporary firewall rules
Publication Date: 2025.12.04 CALYPTIX SECURITY CORP
  • US20250373583A1 patent drawing
  • US20250373583A1 patent drawing
  • US20250373583A1 patent drawing

AI summary

A network security system provides portals which enable automatic creation of a dynamic one-time port forwarding rule for an authorized user's current IP address following two factor authentication of the authorized user. Such a dynamic one-time port forwarding rule is utilized to set up a connection, at which point the dynamic one-time port forwarding rule is removed, preventing any attacker from subsequently taking advantage of it. Such a methodology is advantageous as compared to conventional port forwarding in that it is much more secure. Such a methodology is advantageous as compared to traditional port forwarding with access control both in that a user does not always have to utilize the same device with a static IP address, and in that the port forwarding rule representing or exposing a potential vulnerability is deleted after a connection is established.