Direct Cloud Access Gateway for Secure Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software developers face challenges in directly accessing and managing production networks due to address conflicts, compromised data security from manual configuration of authentication and encryption, and the need for redundant devices to manage different networks.

Innovation Solution

A Direct Cloud Access (DCA) computing system that establishes a VPN connection between developer computing devices and production networks, using a private network to facilitate secure and isolated access, automatically configuring encryption and authentication, and allowing seamless switching between networks while maintaining the developer's desktop experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of authentication and encryption is implemented for each production network, then data security requirements can be met, but configuration time increases and error rates increase

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service through automatic authentication and encryption configuration. The gateway device automatically configures the developer computing device with the appropriate authentication credentials and encryption settings for the target production network, eliminating manual configuration efforts and reducing errors while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway device acts as an intermediary between the developer computing device and production networks. It automatically manages authentication and encryption configurations, serving as a mediator that handles the complex security setup without requiring manual intervention from developers, thus reducing configuration time and errors while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If developer computing devices are manually configured for each production network's authentication and encryption, then security requirements are met, but configuration complexity and error risk increase

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service through automatic authentication and encryption configuration. The gateway device automatically configures the developer computing device with the appropriate authentication credentials and encryption settings for the target production network, eliminating manual configuration efforts and reducing errors while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway device acts as an intermediary between the developer computing device and production networks. It automatically manages authentication and encryption configurations, serving as a mediator that handles the complex security setup without requiring manual intervention from developers, thus reducing configuration time and errors while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If direct connection to production networks is allowed, then access efficiency improves, but network isolation and security are compromised

Engineering Contradiction:
Improveaccess efficiencyVSAvoidnetwork isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The gateway device serves as an intermediary that enables efficient direct access to production networks while maintaining network isolation. It establishes secure connections between developer computing devices and production networks, allowing high-speed data transfer while enforcing security policies and maintaining the isolated nature of production networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements local quality by providing different connection characteristics for different networks. The gateway device establishes dedicated, optimized connection paths for each production network, allowing efficient access tailored to each network's specific requirements while maintaining the isolation and security characteristics of each individual production network.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If multiple redundant devices are used to manage different production networks, then network management capability improves, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork management capabilityVSAvoidnumber of devices
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway device embodies universality by being capable of managing connections to multiple different production networks with varying authentication and encryption requirements through a single device. It can dynamically adapt to different network configurations, eliminating the need for multiple specialized devices while maintaining the ability to manage diverse production networks effectively.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10826874B2Direct production network access using private networks and encapsulation
Publication Date: 2020.11.03 MASTERCARD INT INC
  • US10826874B2 patent drawing
  • US10826874B2 patent drawing
  • US10826874B2 patent drawing

AI summary

A direct cloud access (DCA) computing system for enabling access by a developer computing device hosted on a development network to a plurality of production networks hosted on a cloud services platform is provided. The DCA system includes a development private network interface to a private network, and a production private network interface to the private network. The DCA system further includes a plurality of DCA computing devices each coupled to a respective one of the plurality of production networks. Each DCA is programmed to establish a first VPN connection with a developer computing device on the development network via the private network, receive a client VPN packet addressed to the first DCA network address, and transmit the packet to the production computing device based on a resource address.