Cloud Multi-Perimeter Firewall Routing for Secure, Low-Latency WANs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network optimization technologies, such as WAN optimization and VPNs, often result in high latency and lack control over traffic flow, leading to poor user experience and increased costs due to reliance on fixed point-to-point connections or unstable internet routes, especially when connecting remote LANs to cloud-based servers.

Innovation Solution

A Global Virtual Network (GVN) utilizing a mesh of distributed firewall devices in the cloud, with advanced smart routing and automated systems to optimize traffic flow over standard internet connections, ensuring secure, reliable, and fast connectivity through encrypted tunnels and dynamic path selection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed firewall devices are deployed at multiple perimeters in the cloud, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firewall system is segmented into multiple distributed firewall devices deployed at different perimeters in the cloud. Each firewall device operates independently to provide security at specific network boundaries, allowing the system to achieve comprehensive security coverage while maintaining manageable complexity through modular deployment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A control plane acts as an intermediary between the distributed firewall devices and network administrators. This control plane coordinates firewall policies, manages device configurations, and provides centralized visibility, thereby simplifying the operational complexity of managing multiple distributed firewalls while maintaining enhanced security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traffic is routed through multiple perimeters in the cloud, then network security is improved, but latency increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically selects traffic paths through the distributed firewall perimeters based on real-time network conditions, security requirements, and performance metrics. This dynamic routing capability allows traffic to bypass unnecessary perimeter hops when security risks are low, thereby reducing latency while maintaining security when needed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different perimeter firewalls are configured with specialized security functions based on their local network context and threat profiles. This allows traffic to be inspected only at perimeters where specific security concerns exist, rather than forcing all traffic through every perimeter, thus reducing unnecessary latency while maintaining comprehensive security coverage

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4325804B1Multi-perimeter firewall in the cloud
Publication Date: 2025.10.01 UMBRA TECH LTD
  • EP4325804B1 patent drawingFigure 1
  • EP4325804B1 patent drawingFigure 2
  • EP4325804B1 patent drawingFigure 3

AI summary

A method for a secure boot-up mechanism is provided. The method involves initiating a boot-up process for a computer system, wherein the boot-up process includes accessing an encrypted volume of the computer system. A secure tunnel is built to a remote server storing a decryption key for the encrypted volume. The decryption key is received from the remote server via the secure tunnel, and the encrypted volume is decrypted using the decryption key. A system and non-transitory computer-readable medium is also provided.