IP Library Granted Patent US 12,615,237
Granted Patent B2
US 12,615,237 · App. 18/886,335 · Granted Apr 28, 2026

System and method for utilization of firewall policies for network security

Inventor: Robert Whelton (Louisville, CO)
Assignee: Level 3 Communications, LLC
H04L63/0263H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,237
App. No.
18/886,335
Granted
Apr 28, 2026
Kind
B2
Abstract

Aspects of the present disclosure involve systems, methods, for encoding a firewall ruleset into one or more bit arrays for fast determination of processing of a received communication packet by a firewall device associated with a network. Through this bitmap, a number of computation operations needed to determine a processing rule for a received packet is significantly reduced compared to the traditional approach of using a hash or a longest prefix match technique. Rather, determining a processing rule for a received packet may include determining a bit value within one or more arrays. In one implementation, a firewall rule may be encoded into a 64-bit array of bit values in which each bit of the array corresponds to a particular processing rule for a particular network address. The firewall rule may be encoded into a bitmap array of bit values by asserting a particular bit within the array.

Claims (35)

1 . A method for providing a firewall service, the method comprising:

encoding a firewall ruleset into one or more arrays comprising a string of bits, wherein each bit of the one or more arrays corresponds to one processing rule of the firewall ruleset;

determining a bit value from the one or more arrays based on a first portion of a network address included in a received communication packet; and

processing the received communication packet based on the bit value from the one or more arrays.

2 . The method of claim 1 wherein encoding the firewall ruleset comprises: determining a first type of processing rule for a first rule of the firewall ruleset; and accessing, at an address of a data structure corresponding to a second portion of a network address included in the first rule, a first array of bits corresponding to the first type of processing rule.

3 . The method of claim 2 wherein the network address is an Internet Protocol (IP) address and the first portion comprises a first twenty-six bits of the network address.

4 . The method of claim 2 wherein the first type of processing rule is at least one of a deny processing action, an allow processing action, or a re-routing processing action.

5 . The method of claim 2 wherein the one or more arrays are obtained from a data structure, wherein the data structure comprises a plurality of arrays stored at an address corresponding to the first portion of the network address, each of the plurality of arrays corresponding to a different communication packet processing action.

6 . The method of claim 2 wherein encoding the firewall ruleset further comprises: asserting a bit of the first array of bits at a first bit position, the first bit position corresponding to a value equal to a second portion of the network address.

7 . The method of claim 6 wherein the second portion comprises a last six bits of the network address.

8 . The method of claim 1 , further comprising:

determining, based on the network address including the received communication packet, an identifier of a receiving network; and

selecting a data structure from a plurality of data structures as corresponding to the identifier of the receiving network.

9 . The method of claim 1 wherein the first array of bits comprises 64 bits.

10 . The method of claim 1 wherein processing the received communication packet comprises blocking the received communication to a destination address if the bit value from the one or more arrays is asserted.

11 . The method of claim 1 wherein processing the received communication packet comprises transmitting the received communication to a destination address if the bit value from the one or more arrays is asserted.

12 . A network firewall device comprising:

a processing device;

at least one interface receiving communication packets; and

a non-transitory computer-readable medium encoded with instructions, when executed by the processing device, cause the processing device to perform the operations of:

encoding a firewall ruleset into one or more arrays comprising a string of bits, wherein each bit of the one or more arrays corresponds to one processing rule of the firewall ruleset;

determining a bit value from the one or more arrays based on a first portion of a network address included in a received communication packet; and

processing the received communication packet based on the bit value from the one or more arrays.

13 . The network firewall device of claim 12 wherein encoding the firewall ruleset comprises:

determining a first type of processing rule for a first rule of the firewall ruleset; and

accessing, at an address of a data structure corresponding to a second portion of a network address included in the first rule, a first array of bits corresponding to the first type of processing rule.

14 . The network firewall device of claim 13 wherein the network address is an Internet Protocol (IP) address and the second portion comprises a first twenty-six bits of the network address.

15 . The network firewall device of claim 13 wherein the first type of processing rule is at least one of a deny processing action, an allow processing action, or a re-routing processing action.

16 . The network firewall device of claim 13 wherein the one or more arrays are obtained at a data structure, wherein the data structure comprises a plurality of arrays stored at an address corresponding to the first portion of the network address, each of the plurality of arrays corresponding to a different communication packet processing action.

17 . The network firewall device of claim 13 wherein encoding the firewall ruleset further comprises: asserting a bit of the first array of bits at a first bit position, the first bit position corresponding to a value equal to a second portion of the network address.

18 . The network firewall device of claim 17 wherein the second portion comprises a last six bits of the network address.

19 . The network firewall device of claim 12 wherein the instructions, when executed by the processing device, further cause the processing device to perform the operations of:

determining, based on the network address including the received communication packet, an identifier of a receiving network; and

selecting the data structure from a plurality of data structures as corresponding to the identifier of the receiving network.

20 . The network firewall device of claim 19 wherein the first array of bits comprises 64 bits.

Assignments (3)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2024
From: WHELTON, ROBERT
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 068626/0484 →
Continuity (3)
Continuation 17991322 · Nov 21, 2022
Provisional Application 63283038 · Nov 24, 2021
Related Publication 20250047643A1 · Feb 6, 2025
References Cited (10)
US 10341296B2 · Bhagwat · 2019 [cited by examiner]
US 20080279109A1 · Furman · 2008 [cited by examiner]
US 20100325429A1 · Saha · 2010 [cited by applicant]
US 20170041294A1 · Tulasi · 2017 [cited by examiner]
US 20180167363A1 · Jain · 2018 [cited by examiner]
US 20180351818A1 · Mohanram · 2018 [cited by applicant]
US 20190342225A1 · Sanghi · 2019 [cited by applicant]
US 20200106745A1 · Glazemakers · 2020 [cited by examiner]
US 20200329054A1 · Bjarnason · 2020 [cited by applicant]
US 20230164118A1 · Whelton · 2023 [cited by applicant]