Virtual Host Security Profiles for Multi-Homed Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-homed machines connected to multiple networks face connectivity issues due to restrictive firewall profiles, as existing systems select the most restrictive profile, hindering seamless communication across different networks.

Innovation Solution

The implementation of virtual security profiles, each with specific sets of rules for different network address ranges, allows for seamless concurrent connectivity by creating and applying distinct firewall profiles for each network connection, ensuring secure and unrestricted communication across multiple networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the most restrictive firewall profile is selected for multi-homed machines, then security is improved, but connectivity and convenience deteriorate

Engineering Contradiction:
Improvefirewall securityVSAvoidconnectivity convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the single firewall profile into multiple virtual host profiles (work, home, public) that can be independently applied to different network interfaces. Each profile contains specific security rules tailored to its network type, allowing the firewall to segment security policies by network context rather than applying a single restrictive profile to all connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall dynamically selects and applies appropriate virtual host profiles based on the active network interface and detected network type. The system automatically transitions between profiles as network connections change, enabling adaptive security that adjusts to the current network context without manual intervention or excessive restrictiveness.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If a single firewall profile is applied to all network connections, then device complexity is reduced, but adaptability to different networks deteriorates

Engineering Contradiction:
Improvefirewall configurationVSAvoidnetwork adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The firewall system implements multiple virtual host profiles that can be universally applied across different network interfaces. Each profile is designed to handle specific network types (work, home, public), giving the firewall multi-functionality to adapt to various network environments while maintaining a unified management interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically detects the network type and selects the appropriate virtual host profile without requiring manual configuration or user intervention. The firewall self-services by monitoring active network interfaces and applying the correct profile based on detected network characteristics, reducing the need for complex manual setup.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2499777B1Virtual host security profiles
Publication Date: 2020.10.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2499777B1 patent drawingFigure 1
  • EP2499777B1 patent drawingFigure 2
  • EP2499777B1 patent drawingFigure 3

AI summary

Architecture that creates and applies a virtual firewall profile for each network to which a multi-homed device is connected. In one implementation, the virtual profiles can be based on address ranges of the networks. This ensures seamless concurrent connectivity of the multi-homed device to multiple networks.