IP Library › Granted Patent US 11,805,001
Granted Patent B2
US 11,805,001 · App. 17/473,463 · Granted Oct 31, 2023

Managing data schema differences by path deterministic finite automata

Inventor: Kari J. Nurmela (Helsinki, FI)
Assignee: FORCEPOINT LLC
H04L41/0266H04L49/552H04L49/555
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,001
App. No.
17/473,463
Granted
Oct 31, 2023
Kind
B2
Abstract

A method for migrating a data schema comprising combining a first deterministic finite automaton with a second deterministic finite automaton to generate a modified deterministic finite automation. Identifying a state of the modified deterministic finite automaton without computed followers. Computing a new vector of original states for each state of the modified deterministic finite automaton corresponding to the identified state.

Claims (28)

1. A method for migrating a data schema, comprising:

combining a first deterministic finite automaton configured for use in firewall processing of network data with a second deterministic finite automaton configured for use in firewall processing of network data using a processor operating under algorithmic control to generate a modified deterministic finite automation;

computing a new vector of original states for each state of the modified deterministic finite automaton corresponding to the identified state using the processor to migrate data from the first deterministic finite automaton to the second deterministic finite automaton for use in firewall processing of network data; and

merging firewall-specific metadata from the first deterministic finite automaton with firewall-specific metadata from the second deterministic finite automaton for each state of the modified deterministic finite automaton corresponding to the identified state.

2. The method of claim 1 further comprising:

determining whether the merged metadata is an error state associated with an unsupported feature; and

generating a user direction on a user interface device identifying the error state associated with the unsupported feature if the merged metadata is the error state associated with the unsupported feature.

3. The method of claim 2 further comprising adding the merged metadata to a combined deterministic finite automaton if the merged metadata is not the error state associated with the unsupported feature.

4. The method of claim 3 further comprising generating a transition from the state of the modified deterministic finite automaton to a new state that omits a transition to the error state associated with the unsupported feature.

5. The method of claim 2 wherein determining whether the merged metadata is the error state comprises determining whether the merged metadata includes an unresolvable conflict.

6. The method of claim 2 wherein determining whether the merged metadata is the error state comprises determining whether the new vector includes an error state.

7. The method of claim 1 wherein the first deterministic finite automaton is associated with a schema of a firewall system.

8. The method of claim 1 wherein the first deterministic finite automaton is associated with a schema of a firewall system that includes at least one name and at least one Internet protocol address.

9. A system for migrating a data schema, comprising:

one or more processors with memory configured to execute one or more algorithms that perform the steps of:

combining a first deterministic finite automaton configured for use by a first network firewall with a second deterministic finite automaton configured for use by a second network firewall to generate a modified deterministic finite automation

computing a new vector of original states for each state of the modified deterministic finite automaton corresponding to the identified state to migrate data from the first deterministic finite automaton to the second deterministic finite automaton for use in firewall processing of network data; and

merging firewall-specific metadata from the first deterministic finite automaton with firewall-specific metadata from the second deterministic finite automaton for each state of the modified deterministic finite automaton corresponding to the identified state.

10. The system of claim 9 wherein the one or more algorithms are further configured to perform the step of merging firewall-specific metadata from the first deterministic finite automaton with firewall-specific metadata from the second deterministic finite automaton for each state of the modified deterministic finite automaton corresponding to the identified state.

11. The system of claim 10 wherein the one or more algorithms are further configured to perform the steps of:

determining whether the merged metadata is an error state in a vector; and

generating a user direction on a user interface device identifying the error state if the merged metadata is an error state.

12. The system of claim 11 wherein the one or more algorithms are further configured to perform the step of adding the merged metadata to a combined deterministic finite automaton if the merged metadata is not an error state.

13. The system of claim 12 wherein the one or more algorithms are further configured to perform the step of generating a transition from the state of the modified deterministic finite automaton to a new state.

14. The system of claim 11 wherein the one or more algorithms are further configured to perform the step of determining whether the merged metadata includes an unresolvable conflict.

15. The system of claim 11 wherein the one or more algorithms are further configured to perform the step of determining whether the new vector includes an error state.

16. The system of claim 9 wherein the first deterministic finite automaton is associated with a schema of a firewall system.

17. The system of claim 9 wherein the first deterministic finite automaton is associated with a schema of a firewall system that includes at least one name and at least one Internet protocol address.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2026
From: FORCEPOINT LLC
To: FORCEPOINT QUARRY SOLUTIONS LLC
Reel/Frame 076162/0094 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2021
From: NURMELA, KARI J.
To: FORCEPOINT LLC
Reel/Frame 057465/0476 →
Continuity (2)
Continuation 16541304 · Aug 15, 2019
Related Publication 20210409257A1 · Dec 30, 2021