Cloud-Based Explicit Proxy for Dynamic Edge Firewall Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall systems require users to be on a protected network, limiting edge protection for users connected to public networks, and cloud-based firewall services often lack user control and flexibility, especially for roaming users.

Innovation Solution

A cloud-based Dynamic Edge Protection (DEP) system using an explicit proxy and DNS cache resolver, configured with a proxy auto-configuration file, allows users to access firewall services from any location by forwarding traffic through a cloud-hosted next-generation firewall, enabling dynamic user protection and policy integration between Internet-facing and private access firewall policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firewall services are provided locally for public network-connected users, then firewall protection is available, but users must be on a protected network and local installation is required

Engineering Contradiction:
Improvefirewall service accessibilityVSAvoiduser configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based explicit proxy as an intermediary between users on public networks and the firewall service. The proxy is automatically configured on user devices and forwards traffic to cloud-based firewall processing, eliminating the need for local firewall installation while maintaining protection. This resolves the contradiction by providing firewall services to public network users through a mediating proxy component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based explicit proxy serves multiple functions: it acts as a configuration manager that automatically sets up firewall policies, a traffic forwarder that routes user traffic to cloud firewall services, and an adaptation layer that enables public network users to access protected resources. This multi-functionality allows the system to provide firewall protection universally across different network environments without requiring separate local installations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If cloud-based firewall services are provided, then users can access firewall services from any location, but users have limited control and flexibility

Engineering Contradiction:
Improveremote access capabilityVSAvoiduser control flexibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system dynamically adapts firewall policies based on user context and network conditions. The explicit proxy automatically adjusts configuration parameters such as proxy servers, ports, and policy rules based on the user's location, device type, and access requirements. This dynamic behavior enables remote access while maintaining user control and flexibility through context-aware policy adjustment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The cloud-based firewall system implements feedback mechanisms where user actions and network conditions are monitored and used to adjust firewall policies in real-time. The system receives feedback from users about access requirements and automatically modifies policy configurations to balance security with user control, allowing remote users to maintain flexibility while accessing firewall services from any location.

Inventive Principle:
Principle #23Feedback

3Reliability

If separate policies are used for Internet-facing and private access firewall policies, then security coverage is comprehensive, but policy management is complex

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges Internet-facing firewall policies and private access firewall policies into a unified cloud-based policy management system. The explicit proxy consolidates multiple policy sets and automatically applies the appropriate policies based on traffic destination and user context. This merging maintains comprehensive security coverage for both Internet and private resources while simplifying policy management by eliminating the need to separately configure and maintain distinct policy sets.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified firewall policy system serves multiple functions: it manages both Internet-facing and private access policies, automatically selects appropriate policies based on traffic type, and provides consistent security enforcement across different network environments. This universal policy management approach maintains comprehensive security coverage while reducing complexity by providing a single interface for managing all firewall policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12015594B2Policy integration for cloud-based explicit proxy
Publication Date: 2024.06.18 FORCEPOINT LLC
  • US12015594B2 patent drawing
  • US12015594B2 patent drawing
  • US12015594B2 patent drawing

AI summary

A system for processing data that includes a first processor configured to operate one or more algorithms to provide a proxy for each of a plurality of external network communications segments and internal network communications segments associated with a specific use, the first processor configured to operate one or more algorithms to provide a firewall agent that performs firewall processing for each of the plurality of external network communications segments and the internal network communications segments and wherein the explicit proxy is installed using a proxy auto configuration file that is associated with the firewall agent.