Cloud-Based Explicit Proxy for Dynamic Edge Firewall Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewall systems require users to be on a protected network, limiting edge protection for users connected to public networks, and cloud-based firewall services often lack user control and flexibility, especially for roaming users.
Innovation Solution
A cloud-based Dynamic Edge Protection (DEP) system using an explicit proxy and DNS cache resolver, configured with a proxy auto-configuration file, allows users to access firewall services from any location by forwarding traffic through a cloud-hosted next-generation firewall, enabling dynamic user protection and policy integration between Internet-facing and private access firewall policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firewall services are provided locally for public network-connected users, then firewall protection is available, but users must be on a protected network and local installation is required
Solution Approach 1:
The patent introduces a cloud-based explicit proxy as an intermediary between users on public networks and the firewall service. The proxy is automatically configured on user devices and forwards traffic to cloud-based firewall processing, eliminating the need for local firewall installation while maintaining protection. This resolves the contradiction by providing firewall services to public network users through a mediating proxy component.
Solution Approach 2:
The cloud-based explicit proxy serves multiple functions: it acts as a configuration manager that automatically sets up firewall policies, a traffic forwarder that routes user traffic to cloud firewall services, and an adaptation layer that enables public network users to access protected resources. This multi-functionality allows the system to provide firewall protection universally across different network environments without requiring separate local installations.
2Adaptability or versatility
If cloud-based firewall services are provided, then users can access firewall services from any location, but users have limited control and flexibility
Solution Approach 1:
The system dynamically adapts firewall policies based on user context and network conditions. The explicit proxy automatically adjusts configuration parameters such as proxy servers, ports, and policy rules based on the user's location, device type, and access requirements. This dynamic behavior enables remote access while maintaining user control and flexibility through context-aware policy adjustment.
Solution Approach 2:
The cloud-based firewall system implements feedback mechanisms where user actions and network conditions are monitored and used to adjust firewall policies in real-time. The system receives feedback from users about access requirements and automatically modifies policy configurations to balance security with user control, allowing remote users to maintain flexibility while accessing firewall services from any location.
3Reliability
If separate policies are used for Internet-facing and private access firewall policies, then security coverage is comprehensive, but policy management is complex
Solution Approach 1:
The patent merges Internet-facing firewall policies and private access firewall policies into a unified cloud-based policy management system. The explicit proxy consolidates multiple policy sets and automatically applies the appropriate policies based on traffic destination and user context. This merging maintains comprehensive security coverage for both Internet and private resources while simplifying policy management by eliminating the need to separately configure and maintain distinct policy sets.
Solution Approach 2:
The unified firewall policy system serves multiple functions: it manages both Internet-facing and private access policies, automatically selects appropriate policies based on traffic type, and provides consistent security enforcement across different network environments. This universal policy management approach maintains comprehensive security coverage while reducing complexity by providing a single interface for managing all firewall policies.
Data Source
AI summary
A system for processing data that includes a first processor configured to operate one or more algorithms to provide a proxy for each of a plurality of external network communications segments and internal network communications segments associated with a specific use, the first processor configured to operate one or more algorithms to provide a firewall agent that performs firewall processing for each of the plurality of external network communications segments and the internal network communications segments and wherein the explicit proxy is installed using a proxy auto configuration file that is associated with the firewall agent.


