Virtual Firewall via Switch and Virtual Function

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Migrating services to virtualized networks poses challenges due to increased complexity in accommodating message routing and scaling, especially when transitioning from dedicated infrastructure to virtualized environments.

Innovation Solution

A basic firewall is created using a virtual networking function, comprising a virtual switch and a basic firewall virtual function, which can be instantiated and managed by a control system, allowing for flexible configuration and filtering of traffic at the transport layer without application layer involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If services are migrated to virtualized networks, then flexibility in scaling and locating services is improved, but complexity in accommodating message routing and maintaining services increases

Engineering Contradiction:
Improveflexibility in scaling and locating servicesVSAvoidcomplexity in accommodating message routing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component that mediates message routing between service components in the virtualized network. The virtual switch handles the complexity of routing, filtering, and forwarding traffic between virtual machines and external networks, thereby reducing the routing complexity burden on individual services while maintaining the flexibility benefits of virtualization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If a basic firewall is created using virtual networking functions, then ease of creation and management is improved, but potential loss of filtering precision compared to dedicated infrastructure may occur

Engineering Contradiction:
Improveease of creation and management of firewallVSAvoidfiltering precision
Core Design Contradiction:
Ease of manufactureVSManufacturing precision

Solution Approach 1:

The patent implements a basic firewall virtual function that provides universal firewall capabilities across multiple services and virtual machines. The virtual switch incorporates firewall functionality that can be applied consistently across different service components, enabling easy creation and management of firewall rules while maintaining adequate filtering precision for general security requirements through standardized rule sets.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If firewall functionality is integrated into virtual networking functions, then device complexity is reduced, but potential loss of specialized firewall performance may occur

Engineering Contradiction:
Improvecomplexity of firewall managementVSAvoidfirewall performance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges firewall functionality with virtual networking functions by integrating the basic firewall virtual function into the virtual switch infrastructure. This consolidation reduces overall device complexity by eliminating separate dedicated firewall appliances while maintaining adequate filtering performance through the combined networking and security functions provided by the virtual switch.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10154009B2Providing a basic firewall using a virtual networking function
Publication Date: 2018.12.11 AT&T INTELLECTUAL PROPERTY I L P
  • US10154009B2 patent drawing
  • US10154009B2 patent drawing
  • US10154009B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for providing a basic firewall using a virtual networking function. A control system having a processor can detect a firewall request that can include a request to create a basic firewall. The processor can analyze a recipe to determine a virtual switch and a basic firewall virtual function that are to provide the functionality of the basic firewall. The processor can trigger instantiation of the virtual switch via a network control function and instantiation of the basic firewall virtual function via a service control function. The processor also can validate the basic firewall. The basic firewall can provide filtering of traffic at the network transport layer using the virtual switch, and as such, the virtual switch may not operate on the application layer.