Cloud Multi-Perimeter Firewalls for Dynamic Tunnel Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network optimization technologies, such as WAN optimization and VPNs, often result in high latency and lack control over traffic flow, leading to poor user experience and increased costs due to reliance on fixed point-to-point connections or unstable internet routes, especially when connecting remote LANs to cloud-based servers.
Innovation Solution
A Global Virtual Network (GVN) utilizing a mesh of distributed devices with advanced tunnels, automated routing, and multi-perimeter firewalls in the cloud to optimize secure, reliable, and fast connectivity over standard internet connections, ensuring data flow through the best communication paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If WAN optimization with hardware devices is used to compress and secure data flow, then transmission cost is reduced, but connection stability deteriorates when the internet connection between devices is poor
Solution Approach 1:
The patent introduces a controller as an intermediary device that manages and coordinates multiple WAN optimizers. The controller receives flow control requests from WAN optimizers and distributes control messages to other optimizers, creating a coordinated network that can dynamically adapt to connection conditions. This intermediary structure allows the system to maintain reliability by routing traffic through optimized paths while preserving the cost benefits of compression and secure data flow.
2Reliability
If fixed point-to-point connections or dedicated circuits are used, then connection quality and QOS guarantees are improved, but installation time and cost increase significantly
Solution Approach 1:
The patent implements self-service capabilities through automated flow control mechanisms where WAN optimizers autonomously monitor connection conditions and request flow control adjustments from the controller without manual intervention. The system automatically discovers optimal paths, establishes encrypted tunnels, and dynamically adjusts traffic routing based on real-time network conditions. This automation eliminates the need for time-consuming manual configuration and physical installation of dedicated circuits while maintaining connection quality through intelligent, adaptive resource allocation.
3Adaptability or versatility
If traffic is routed through the internet to access cloud-based servers, then connectivity flexibility is improved, but latency increases due to multiple hops through the network
Solution Approach 1:
The patent implements preliminary action by pre-establishing encrypted tunnels and pre-configuring flow control rules between WAN optimizers before traffic needs to be transmitted. The controller proactively manages tunnel establishment and maintains ready-to-use communication paths between devices. When traffic needs to flow between cloud-based servers, the pre-configured tunnels and flow control mechanisms are already in place, eliminating the need for real-time path discovery and reducing latency while preserving connectivity flexibility through the internet.
4Reliability
If multiple firewalls are deployed at different perimeters, then network security is improved, but system complexity increases
Solution Approach 1:
The patent implements multi-functionality by designing the controller to perform multiple roles: it acts as a central management system for flow control, a coordination hub for tunnel establishment, and a security policy enforcement point. The controller communicates with multiple firewalls at different network perimeters using standardized protocols, enabling centralized security management across distributed firewalls. This universal controller architecture reduces system complexity by consolidating management functions while maintaining robust multi-layered security through coordinated firewall operations.
Data Source
AI summary
Systems and methods for providing multi-perimeter firewalls via a virtual global network are disclosed. In one embodiment the network system may comprise an egress ingress point in communication with a first access point server, a second access point server in communication with the first access point server, an endpoint device in communication with the second access point server, a first firewall in communication with the first access point server, and a second firewall in communication with the second access point server. The first and second firewalls may prevent traffic from passing through their respective access point servers. The first and second may be in communication with each other and exchange threat information.


