Cloud Emulation via Split Private DNS and Proxy Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for emulating a secure, non-public cloud region face difficulties in high-side compatibility, as they often block applications from accessing public Internet websites and cloud services not available on the high-side, leading to integration challenges for customers migrating systems and applications.
Innovation Solution
A method and system that utilize a private domain name system split between customer and private subnets, with a proxy server monitoring and blocking HTTP requests to public Internet websites and endpoint servers redirecting requests to equivalent endpoints within the first cloud computing environment, mimicking the security protocols of a second cloud environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a proxy server blocks HTTP requests to public Internet websites, then security compliance with high-side standards is improved, but application compatibility and ease of operation deteriorate
Solution Approach 1:
The patent employs a proxy server as an intermediary component that sits between the customer subnet and the public Internet. This proxy server mediates all HTTP requests by monitoring, filtering, and blocking requests to public Internet websites while allowing requests to approved endpoints. The intermediary nature of the proxy server enables security compliance to be enforced without requiring direct application changes, thus maintaining application compatibility while achieving security goals.
2Reliability
If endpoint requests are blocked to services not available on the high-side, then security protocol compliance is improved, but integration capability and adaptability worsen
Solution Approach 1:
The patent segments the network into distinct subnets (customer subnet and private subnet) with a proxy server positioned in the private subnet. This segmentation allows differential treatment of network traffic: requests to high-side approved endpoints are permitted and routed appropriately, while requests to public Internet websites or unauthorized services are blocked. The segmented architecture enables selective enforcement of security protocols on different traffic types, maintaining integration capability for authorized services while blocking unauthorized access.
3Measurement precision
If a private domain name system is implemented to mimic a second cloud environment, then emulation accuracy and measurement precision are improved, but system complexity increases
Solution Approach 1:
The patent implements a private domain name system that copies and mimics the domain name resolution functionality of the target second cloud environment. This copying approach allows applications to be tested in the first cloud environment with high fidelity to the target environment's naming and resolution behavior. The DNS copying enables accurate emulation of the second cloud's network architecture without requiring physical replication of the entire target system, thus achieving high emulation accuracy while managing system complexity through virtualization and software-based DNS services.
Data Source
AI summary
A system and a method of emulating a second cloud computing environment on a first cloud computing environment are disclosed herein. The first cloud computing environment includes an innovation platform having a private domain name system. The private domain name system is split between a customer subnet and a private subnet. The customer subnet is limited to communications with only the private subnet. The customer subnet executes an application thereon. The application is targeted for use on the second cloud computing environment.


