Outer Rim Archives
Archives · 2023 · 11695732

Granted patent

Architecture features for a media-centric firewall

Number
11695732
Published
2023-07-04
Filed
2021-05-13
Assignee
Disney Enterprises Inc.
Inventors
Strein; Michael J. et al.
CPC
H04L63/0263; H04L63/0807; H04L63/0236; H04L63/20; H04L41/0886; H04L41/082
Verdict
Set aside network security infrastructure
Source
Google Patents · FreePatentsOnline

Abstract

The embodiments herein describe a firewall for a media production system to provide flexible security between an on-premises production environment and remote media production applications and devices (e.g., cloud-based virtual production environments). As new media devices and applications (referred to generally as media nodes) are added at remote locations, the firewall is updated to permit the media nodes to communicate with the on-premises production environment. The embodiments herein described an automatic (e.g., software driven) process where a network orchestrator can detect a change in the media nodes and update the rule set in the firewall accordingly.

Background

BACKGROUND (1) Security in media networks has traditionally been managed using so called “air gaps,” in which the media networks are prevented from having external connectivity. As it has become increasingly important for media network nodes to connect to resources outside of a local environment, such as to a post-production facility or an Internet connected feed for example, security has typically been provided through the manual management of destination Internet Protocol (IP) addresses, the manual opening of switch ports, and the manual configuration of firewalls. However, as media production migrates from traditional on-premises production facilities to cloud-based production resources requiring the transport of media flows into and out of a public cloud, there is a need in the art for a nimble security solution capable of ensuring media flow integrity in a dynamic network environment. SUMMARY (2) One embodiment described herein is a method and a computer readable medium that includes providing a silo in a firewall containing a rule set that is preauthorized for dynamic changes where the firewall protects an on-premises media production environment, detecting at least one of an addition or a subtraction of a media node in a remote media production environment, generating a rule change for the firewall that at least one of (i) permits an added media node to communicate with the on-premises media production environment or (ii) prohibits a subtracted media node from communic

Claims

1. A method, comprising: providing a silo in a firewall containing a rule set that is preauthorized for dynamic changes, wherein the firewall protects an on-premises media production environment; detecting at least one of an addition or a subtraction of a media node in a remote media production environment; generating a rule change for the firewall that at least one of (i) permits an added media node to communicate with the on-premises media production environment or (ii) prohibits a subtracted media node from communicating with the on-premises media production environment; transmitting the rule change to the firewall; and upon determining, at the firewall, that the rule change affects the rule set in the silo, updating the rule set based on the rule change. || 9. A system comprising: a local network configured to provide a service; a firewall configured to protect the local network from unauthorized access, wherein the firewall comprises: a first silo containing a first rule set preauthorized for dynamic changes, and a second silo containing a second rule set that is not authorized for dynamic changes; and a network orchestrator configured to: detect at least one of an addition or a subtraction of a computing resource in a remote network, wherein the computing resource is configured to perform tasks corresponding to the service in the local network, generate a rule change for the firewall that at least one of (i) permits an added computing resource to communicate with the service in the local network or (ii) prohibits a subtracted computing resource from communicating with the local network, and transmit the rule change to the firewall, wherein the firewall is configured to update the first rule set based on the rule change only after determining the rule change affects the first rule set in the first silo and not the second rule set in the second silo. || 16. A non-transitory computer readable medium having program instructions embodied therewith, the program instructions executable by a processor to perform an operation, the operation comprising: providing a silo in a firewall containing a rule set that is preauthorized for dynamic changes, wherein the firewall protects an on-premises media production environment; detecting at least one of an addition or a subtraction of a media node in a remote media production environment; generating a rule change for the firewall that at least one of (i) permits an added media node to communicate with the on-premises media production environment or (ii) prohibits a subtracted media node from communicating with the on-premises media production environment; transmitting the rule change to the firewall; and upon determining, at the firewall, that the rule change affects the rule set in the silo, updating the rule set based on the rule change.