Bridging Infrastructure for Secure Cloud-to-On-Premises Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public cloud hosting platforms face challenges in accessing resources located within private networks due to security, compliance, or legal constraints, requiring network administrators to open firewall ports, deploy proxies, or establish VPN connections.

Innovation Solution

A bridging infrastructure within the public cloud is provisioned to connect with on-premises resources in private networks, using application-specific credentials and a proxy on the private network for secure outbound communication, eliminating the need for opening firewall ports or establishing VPN connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If resources are moved to the public cloud to be used by applications, then accessibility and scalability are improved, but security and compliance requirements cannot be met for resources that must remain in private networks

Engineering Contradiction:
Improveaccessibility of resourcesVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hybrid connection infrastructure that acts as an intermediary between public cloud applications and private network resources. This intermediary enables secure access to private resources from the public cloud without moving the resources themselves, thus maintaining security and compliance while achieving accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network administrators open firewall ports or deploy proxies to allow access to private network resources, then connectivity is improved, but network security and complexity increase

Engineering Contradiction:
Improveconnectivity to private resourcesVSAvoidfirewall configuration and proxy deployment
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The hybrid connection infrastructure provides a universal solution that replaces multiple separate mechanisms (firewall port opening, proxy deployment, VPN setup) with a single integrated system. This multi-functional approach simplifies network administration while maintaining connectivity to private resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The hybrid connection acts as an intermediary that eliminates the need for network administrators to directly configure firewalls or deploy proxies. The intermediary handles the connectivity requirements automatically, reducing administrative complexity and network security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If VPN connections are established to access private network resources from the public cloud, then secure access is improved, but setup complexity and maintenance overhead increase

Engineering Contradiction:
Improvesecure accessVSAvoidVPN configuration and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hybrid connection infrastructure serves as an intermediary that provides secure access to private network resources without requiring traditional VPN configurations. It handles authentication, encryption, and connection management automatically, maintaining security while eliminating setup and maintenance complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hybrid connection system enables self-service capabilities where applications in the public cloud can automatically connect to private network resources without manual VPN configuration. The system handles connection establishment, authentication, and management automatically, reducing maintenance overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3143745B1Connecting public cloud with private network resources
Publication Date: 2020.10.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3143745B1 patent drawingFigure 1
  • EP3143745B1 patent drawingFigure 2
  • EP3143745B1 patent drawingFigure 3~4

AI summary

The automatic establishing of the connection between the public cloud and the on- premises resource. First, the bridging infrastructure is automatic accessed. The bridging infrastructure is configured to interact with a user system within the private network using a first control. For instance, it is this first control that may be represented as an executable within the configuration package used in provisioning the connection. A second control is provided to the application running in the public cloud. The second control is structured such that the at least one application may be used to securely connect via the bridging infrastructure with an on-premises resource of the private network.