Cloud Emulation via Split Private DNS and Proxy Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for emulating a secure, non-public cloud region face difficulties in high-side compatibility, as they often block applications from accessing public Internet websites and cloud services not available on the high-side, leading to integration challenges for customers migrating systems and applications.

Innovation Solution

A method and system that utilize a private domain name system split between customer and private subnets, with a proxy server monitoring and blocking HTTP requests to public Internet websites and endpoint servers redirecting requests to equivalent endpoints within the first cloud computing environment, mimicking the security protocols of a second cloud environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proxy server blocks HTTP requests to public Internet websites, then security compliance with high-side standards is improved, but application compatibility and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity complianceVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent employs a proxy server as an intermediary component that sits between the customer subnet and the public Internet. This proxy server mediates all HTTP requests by monitoring, filtering, and blocking requests to public Internet websites while allowing requests to approved endpoints. The intermediary nature of the proxy server enables security compliance to be enforced without requiring direct application changes, thus maintaining application compatibility while achieving security goals.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If endpoint requests are blocked to services not available on the high-side, then security protocol compliance is improved, but integration capability and adaptability worsen

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidintegration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into distinct subnets (customer subnet and private subnet) with a proxy server positioned in the private subnet. This segmentation allows differential treatment of network traffic: requests to high-side approved endpoints are permitted and routed appropriately, while requests to public Internet websites or unauthorized services are blocked. The segmented architecture enables selective enforcement of security protocols on different traffic types, maintaining integration capability for authorized services while blocking unauthorized access.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If a private domain name system is implemented to mimic a second cloud environment, then emulation accuracy and measurement precision are improved, but system complexity increases

Engineering Contradiction:
Improveemulation accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a private domain name system that copies and mimics the domain name resolution functionality of the target second cloud environment. This copying approach allows applications to be tested in the first cloud environment with high fidelity to the target environment's naming and resolution behavior. The DNS copying enables accurate emulation of the second cloud's network architecture without requiring physical replication of the entire target system, thus achieving high emulation accuracy while managing system complexity through virtualization and software-based DNS services.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11528254B2System and method of emulating a cloud computing environment
Publication Date: 2022.12.13 SEQUOIA HOLDINGS LLC
  • US11528254B2 patent drawing
  • US11528254B2 patent drawing
  • US11528254B2 patent drawing

AI summary

A system and a method of emulating a second cloud computing environment on a first cloud computing environment are disclosed herein. The first cloud computing environment includes an innovation platform having a private domain name system. The private domain name system is split between a customer subnet and a private subnet. The customer subnet is limited to communications with only the private subnet. The customer subnet executes an application thereon. The application is targeted for use on the second cloud computing environment.