IP Library › Granted Patent US 10,367,788
Granted Patent B2
US 10,367,788 · App. 16/001,376 · Granted Jul 30, 2019

Passport-controlled firewall

Inventors: Joachim H. Frank (Tuebingen, DE); Holger Karn (Aidlingen, DE)
Assignee: International Business Machines Corporation
H04L63/0263G07C9/00007H04L9/006H04L9/3268H04L63/0442H04L63/08H04L29/06578H04L63/126H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,788
App. No.
16/001,376
Granted
Jul 30, 2019
Kind
B2
Abstract

A method and system for dynamically modifying rules in a firewall infrastructure. A signed passport, which includes a heart-beat time-out interval and a firewall rule, is received. A trigger signal is generated within the heart-beat time-out interval. The signed passport and the trigger signal are transmitted within the heart-beat time-out interval to a border control agent of a firewall in the firewall infrastructure. In response to receiving, from the border control agent, a continuous confirmation of the firewall rule within a time interval shorter than the heart-beat time-out interval, the firewall is modified according to the firewall rule. In response to determining that the trigger signal was not received by the border control agent within the heart-beat time-out interval, the firewall rule is reset.

Claims (68)

1. A method for dynamically modifying rules in a firewall infrastructure, said method comprising:

receiving, by one or more processors, a signed passport comprising a hash value that includes a heart-beat time-out interval and a firewall rule, said one or more processors being hardware processors;

encrypting, by the one or more processors, the signed passport based on a public key certificate registered with a trusted signer;

generating, by the one or more processors, a trigger signal within the heart-beat time-out interval;

transmitting, by the one or more processors, the signed passport and the trigger signal within the heart-beat time-out interval to a border control agent of a firewall in the firewall infrastructure;

in response to receiving, by the one or more processors from the border control agent, a continuous confirmation of the firewall rule within a time interval shorter than the heart-beat time-out interval, modifying, by the one or more processors, the firewall according to the firewall rule;

in response to determining, by the one or more processors, that the trigger signal was not received by the border control agent within the heart-beat time-out interval, resetting, by the one or more processors, the firewall rule.

2. The method of claim 1 , said receiving comprising receiving an application code, said signed passport further comprising a first application hash value, said method further comprising:

authenticating, by said one or more processors, the received passport;

hashing, by said one or more processors, the received application code, resulting in a second application hash value; and

validating, by the one or more processors, the received first application hash value and the second application hash value as being equal,

wherein said transmitting the signed passport and the trigger signal to the border control agent is in response to said authenticating and said validating.

3. The method of claim 2 , said method further comprising:

communicating, by the one or more processors with the application code, through the modified firewall.

4. The method of claim 1 , said method further comprising:

in response to a period of inactivity, closing, by the one or more processors, the firewall.

5. The method of claim 1 , said receiving the signed passport comprising receiving the signed passport during a first time period at a requestor module on a server, said method further comprising:

identifying, by the one or more processors during a second time period, the passport as unsigned; and

in response to a determination, by the or more processors, of an unsecured communication channel between the requestor module and the border control agent:

identifying, by the one or more processors, a signing of the unsigned passport by the requestor module;

encrypting, by the one or more processors, the signed passport with a public key of the border control agent; and

transmitting, by the one or more processors, the encrypted passport through the unsecured communication channel.

6. The method of claim 1 , wherein said encrypting comprising utilizating an asymmetrical encryption method.

7. A computer program product, comprising one or more computer readable hardware storage devices having computer readable program code stored therein, said program code containing instructions executable by one or more processors to implement a method for dynamically modifying rules in a firewall infrastructure, said method comprising:

receiving, by the one or more processors, a signed passport comprising a hash value that includes a heart-beat time-out interval and a firewall rule, said one or more processors being hardware processors;

encrypting, by the one or more processors, the signed passport based on a public key certificate registered with a trusted signer;

generating, by the one or more processors, a trigger signal within the heart-beat time-out interval;

transmitting, by the one or more processors, the signed passport and the trigger signal within the heart-beat time-out interval to a border control agent of a firewall in the firewall infrastructure;

in response to receiving, by the one or more processors from the border control agent, a continuous confirmation of the firewall rule within a time interval shorter than the heart-beat time-out interval, modifying, by the one or more processors, the firewall according to the firewall rule;

in response to determining, by the one or more processors, that the trigger signal was not received by the border control agent within the heart-beat time-out interval, resetting, by the one or more processors, the firewall.

8. The computer program product of claim 7 , said receiving comprising receiving an application code, said signed passport further comprising a first application hash value, said method further comprising:

authenticating, by said one or more processors, the received passport;

hashing, by said one or more processors, the received application code, resulting in a second application hash value; and

validating, by the one or more processors, the received first application hash value and the second application hash value as being equal,

wherein said transmitting the signed passport and the trigger signal to the border control agent is in response to said authenticating and said validating.

9. The computer program product of claim 8 , said method further comprising:

communicating, by the one or more processors with the application code, through the modified firewall.

10. The computer program product of claim 7 , said method further comprising:

in response to a period of inactivity, closing, by the one or more processors, the firewall.

11. The computer program product of claim 7 , said receiving the signed passport comprising receiving the signed passport during a first time period at a requestor module on a server, said method further comprising:

identifying, by the one or more processors during a second time period, the passport as unsigned; and

in response to a determination, by the or more processors, of an unsecured communication channel between the requestor module and the border control agent:

identifying, by the one or more processors, a signing of the unsigned passport by the requestor module;

encrypting, by the one or more processors, the signed passport with a public key of the border control agent; and

transmitting, by the one or more processors, the encrypted passport through the unsecured communication channel.

12. The computer program product of claim 7 , wherein said encrypting comprising utilizating an asymmetrical encryption method.

13. A computer system, comprising one or more processors, one or more memories, and one or more computer readable hardware storage devices, said one or more storage device containing program code executable by the one or more processors via the one or more memories to implement a method for dynamically modifying rules in a firewall infrastructure, said method comprising:

receiving, by the one or more processors, a signed passport comprising a hash value that includes a heart-beat time-out interval and a firewall rule, said one or more processors being hardware processors;

encrypting, by the one or more processors, the signed passport based on a public key certificate registered with a trusted signer;

generating, by the one or more processors, a trigger signal within the heart-beat time-out interval;

transmitting, by the one or more processors, the signed passport and the trigger signal within the heart-beat time-out interval to a border control agent of a firewall in the firewall infrastructure;

in response to receiving, by the one or more processors from the border control agent, a continuous confirmation of the firewall rule within a time interval shorter than the heart-beat time-out interval, modifying, by the one or more processors, the firewall according to the firewall rule;

in response to determining, by the one or more processors, that the trigger signal was not received by the border control agent within the heart-beat time-out interval, resetting, by the one or more processors, the firewall.

14. The computer system of claim 13 , said receiving comprising receiving an application code, said signed passport further comprising a first application hash value, said method further comprising:

authenticating, by said one or more processors, the received passport;

hashing, by said one or more processors, the received application code, resulting in a second application hash value; and

validating, by the one or more processors, the received first application hash value and the second application hash value as being equal,

wherein said transmitting the signed passport and the trigger signal to the border control agent is in response to said authenticating and said validating.

15. The computer system of claim 14 , said method further comprising:

communicating, by the one or more processors with the application code, through the modified firewall.

16. The computer system of claim 13 , said method further comprising:

in response to a period of inactivity, closing, by the one or more processors, the firewall.

17. The computer system of claim 13 , said receiving the signed passport comprising receiving the signed passport during a first time period at a requestor module on a server, said method further comprising:

identifying, by the one or more processors during a second time period, the passport as unsigned; and

in response to a determination, by the or more processors, of an unsecured communication channel between the requestor module and the border control agent:

identifying, by the one or more processors, a signing of the unsigned passport by the requestor module;

encrypting, by the one or more processors, the signed passport with a public key of the border control agent; and

transmitting, by the one or more processors, the encrypted passport through the unsecured communication channel.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2018
From: FRANK, JOACHIM H.; KARN, HOLGER
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046003/0441 →
Continuity (3)
Continuation 15854055 · Dec 26, 2017
Continuation 14821942 · Aug 10, 2015
Related Publication 20180288003A1 · Oct 4, 2018