Cloud Multi-Perimeter Firewalls for Dynamic Tunnel Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network optimization technologies, such as WAN optimization and VPNs, often result in high latency and lack control over traffic flow, leading to poor user experience and increased costs due to reliance on fixed point-to-point connections or unstable internet routes, especially when connecting remote LANs to cloud-based servers.

Innovation Solution

A Global Virtual Network (GVN) utilizing a mesh of distributed devices with advanced tunnels, automated routing, and multi-perimeter firewalls in the cloud to optimize secure, reliable, and fast connectivity over standard internet connections, ensuring data flow through the best communication paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If WAN optimization with hardware devices is used to compress and secure data flow, then transmission cost is reduced, but connection stability deteriorates when the internet connection between devices is poor

Engineering Contradiction:
Improvetransmission costVSAvoidconnection stability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent introduces a controller as an intermediary device that manages and coordinates multiple WAN optimizers. The controller receives flow control requests from WAN optimizers and distributes control messages to other optimizers, creating a coordinated network that can dynamically adapt to connection conditions. This intermediary structure allows the system to maintain reliability by routing traffic through optimized paths while preserving the cost benefits of compression and secure data flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fixed point-to-point connections or dedicated circuits are used, then connection quality and QOS guarantees are improved, but installation time and cost increase significantly

Engineering Contradiction:
Improveconnection qualityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service capabilities through automated flow control mechanisms where WAN optimizers autonomously monitor connection conditions and request flow control adjustments from the controller without manual intervention. The system automatically discovers optimal paths, establishes encrypted tunnels, and dynamically adjusts traffic routing based on real-time network conditions. This automation eliminates the need for time-consuming manual configuration and physical installation of dedicated circuits while maintaining connection quality through intelligent, adaptive resource allocation.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If traffic is routed through the internet to access cloud-based servers, then connectivity flexibility is improved, but latency increases due to multiple hops through the network

Engineering Contradiction:
Improveconnectivity flexibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing encrypted tunnels and pre-configuring flow control rules between WAN optimizers before traffic needs to be transmitted. The controller proactively manages tunnel establishment and maintains ready-to-use communication paths between devices. When traffic needs to flow between cloud-based servers, the pre-configured tunnels and flow control mechanisms are already in place, eliminating the need for real-time path discovery and reducing latency while preserving connectivity flexibility through the internet.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple firewalls are deployed at different perimeters, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by designing the controller to perform multiple roles: it acts as a central management system for flow control, a coordination hub for tunnel establishment, and a security policy enforcement point. The controller communicates with multiple firewalls at different network perimeters using standardized protocols, enabling centralized security management across distributed firewalls. This universal controller architecture reduces system complexity by consolidating management functions while maintaining robust multi-layered security through coordinated firewall operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12432161B2Multi-perimeter firewall in the cloud
Publication Date: 2025.09.30 UMBRA TECHNOLOGIES LTD (UK)
  • US12432161B2 patent drawing
  • US12432161B2 patent drawing
  • US12432161B2 patent drawing

AI summary

Systems and methods for providing multi-perimeter firewalls via a virtual global network are disclosed. In one embodiment the network system may comprise an egress ingress point in communication with a first access point server, a second access point server in communication with the first access point server, an endpoint device in communication with the second access point server, a first firewall in communication with the first access point server, and a second firewall in communication with the second access point server. The first and second firewalls may prevent traffic from passing through their respective access point servers. The first and second may be in communication with each other and exchange threat information.