Edge Gateway Proxy Tunneling for Secure Cloud Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in configuring their on-premises network security to support cloud-based data plane service agents due to varying security configurations and policies, which often require extensive manual updates and can lead to unnecessary access permissions, deterring the adoption of edge device services.

Innovation Solution

A unified platform with a gateway router on edge devices routes outbound requests through a cloud-based gateway, using nested HTTP connections to establish secure tunnels without altering the enterprise's outbound proxy settings, enabling granular control over endpoint access on a per-device basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises configure outbound proxy settings to allow connections to cloud-based service domains, then cloud service connectivity is enabled, but security control and compliance with enterprise policies are compromised

Engineering Contradiction:
Improvecloud service connectivityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based gateway as an intermediary component between edge devices and cloud services. This gateway acts as a mediator that receives connections from edge devices, validates them against enterprise security policies, and establishes appropriate communication channels. The gateway handles the complexity of proxy configuration and security validation centrally, allowing enterprises to maintain security control while enabling cloud service connectivity without modifying individual edge device proxy settings.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If enterprises manually update proxy settings for each cloud service, then service connectivity is established, but configuration complexity and time consumption increase

Engineering Contradiction:
Improveservice connectivityVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements self-service functionality where the cloud-based gateway automatically handles connection establishment and security validation for multiple cloud services. Instead of requiring enterprises to manually configure proxy settings for each service, the gateway autonomously manages these configurations based on pre-established enterprise policies and service requirements. This automation significantly reduces configuration time and complexity while maintaining comprehensive service connectivity.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If enterprises implement granular security policies for each edge device, then security control is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal cloud-based gateway that serves multiple functions: it acts as a security validation endpoint, a connection manager, and a policy enforcement point for all edge devices. This single multi-functional gateway handles security validation and connection establishment for numerous edge devices using unified enterprise policies, eliminating the need for individual complex configurations at each device. The gateway's universal design simplifies management while maintaining granular security control through centralized policy application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12556516B2Edge connectivity gateway
Publication Date: 2026.02.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12556516B2 patent drawing
  • US12556516B2 patent drawing
  • US12556516B2 patent drawing

AI summary

A disclosed method facilitates communications between an edge device and a cloud-based service component via an enterprise proxy without configuring the enterprise proxy to allow access to a service domain associated with the cloud-based service component. The method includes receiving, at a first proxy on the edge device, a service domain connection request from the service agent that specifies a service domain associated with the cloud-based service component. The first proxy responds to the first connection request by transmitting a sequence of nested connection requests including an inner connection request and an outer connection request. The inner connection request establishes a first communication channel between the first proxy and a cloud-based gateway. The outer connection request is transmitted along the first communication channel and establishes a second communication channel between the cloud-based gateway and the service domain requested by the service agent.