Unified Network Firewall for Host and Virtualized Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face security challenges as network firewalls in hosts and virtualized environments often have different policies, leading to reduced security and potential data exfiltration, especially when virtualized environment policies are less strict.

Innovation Solution

Implementing a network firewall between a virtualized environment and a host processing system that applies a consistent firewall policy across both, using a shared policy with the host firewall, and filtering traffic based on unique identifiers, profiles, and port numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network firewalls are implemented in both host and virtualized environments with different policies, then network security coverage is improved, but security consistency deteriorates and data exfiltration risk increases

Engineering Contradiction:
Improvenetwork security coverageVSAvoidfirewall policy consistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent merges the firewall functionality of the host and virtualized environments into a single unified firewall system. The host firewall is extended to directly manage and filter traffic for virtualized environments, eliminating the need for separate virtualized environment firewalls with different policies. This unification ensures that a single consistent firewall policy is applied across all network traffic, whether originating from the host or virtualized environments, thereby maintaining security consistency while providing comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If network firewalls are implemented in virtualized environments with less strict policies, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improvefirewall configuration flexibilityVSAvoiddata exfiltration risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The host firewall is designed with universal functionality to handle both host traffic and virtualized environment traffic through a single interface and policy set. This multi-functional approach allows the firewall to operate with a unified policy that provides strong security protection while remaining easy to manage. Administrators configure one consistent policy for all traffic types, eliminating the need to maintain separate, less strict policies for virtualized environments, thus achieving both ease of operation and high security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If separate network firewalls are used in host and virtualized environments, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvefirewall policy customizationVSAvoidfirewall system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall functionality at the software level while maintaining a unified system architecture. The host firewall includes specialized components that can independently process and apply policies for different traffic types (host traffic vs. virtualized environment traffic). This segmentation allows for customized policy application to different traffic streams while avoiding the complexity of multiple separate firewall systems. The unified architecture with segmented processing provides both adaptability and simplified management.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12463941B2Providing a network firewall between a virtualized environment and a host processing system
Publication Date: 2025.11.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12463941B2 patent drawing
  • US12463941B2 patent drawing
  • US12463941B2 patent drawing

AI summary

A network firewall is disclosed that operates between a virtualized environment and the processing system that provides the virtualized environment. The network firewall filters network traffic generated by and destined for program components executing in the virtualized environment. The network firewall can be located in a hypervisor, a flow steering engine, or at another location between the virtualized environment and the processing system. The network firewall utilizes a firewall policy that can be shared with a network firewall on the processing system that filters network traffic originating at or destined for the processing system. The network firewall can filter network traffic based upon a unique identifier assigned to a virtualized environment, upon port numbers assigned to program components in a virtualized environment, or upon profiles assigned to network interfaces. The network firewall can also filter loopback traffic between a guest operating system (OS) and a host OS.