Edge Gateway Proxy Tunneling for Secure Cloud Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in configuring their on-premises network security to support cloud-based data plane service agents due to varying security configurations and policies, which often require extensive manual updates and can lead to unnecessary access permissions, deterring the adoption of edge device services.
Innovation Solution
A unified platform with a gateway router on edge devices routes outbound requests through a cloud-based gateway, using nested HTTP connections to establish secure tunnels without altering the enterprise's outbound proxy settings, enabling granular control over endpoint access on a per-device basis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If enterprises configure outbound proxy settings to allow connections to cloud-based service domains, then cloud service connectivity is enabled, but security control and compliance with enterprise policies are compromised
Solution Approach 1:
The patent introduces a cloud-based gateway as an intermediary component between edge devices and cloud services. This gateway acts as a mediator that receives connections from edge devices, validates them against enterprise security policies, and establishes appropriate communication channels. The gateway handles the complexity of proxy configuration and security validation centrally, allowing enterprises to maintain security control while enabling cloud service connectivity without modifying individual edge device proxy settings.
2Adaptability or versatility
If enterprises manually update proxy settings for each cloud service, then service connectivity is established, but configuration complexity and time consumption increase
Solution Approach 1:
The patent implements self-service functionality where the cloud-based gateway automatically handles connection establishment and security validation for multiple cloud services. Instead of requiring enterprises to manually configure proxy settings for each service, the gateway autonomously manages these configurations based on pre-established enterprise policies and service requirements. This automation significantly reduces configuration time and complexity while maintaining comprehensive service connectivity.
3Object-affected harmful factors
If enterprises implement granular security policies for each edge device, then security control is improved, but device complexity and management overhead increase
Solution Approach 1:
The patent creates a universal cloud-based gateway that serves multiple functions: it acts as a security validation endpoint, a connection manager, and a policy enforcement point for all edge devices. This single multi-functional gateway handles security validation and connection establishment for numerous edge devices using unified enterprise policies, eliminating the need for individual complex configurations at each device. The gateway's universal design simplifies management while maintaining granular security control through centralized policy application.
Data Source
AI summary
A disclosed method facilitates communications between an edge device and a cloud-based service component via an enterprise proxy without configuring the enterprise proxy to allow access to a service domain associated with the cloud-based service component. The method includes receiving, at a first proxy on the edge device, a service domain connection request from the service agent that specifies a service domain associated with the cloud-based service component. The first proxy responds to the first connection request by transmitting a sequence of nested connection requests including an inner connection request and an outer connection request. The inner connection request establishes a first communication channel between the first proxy and a cloud-based gateway. The outer connection request is transmitted along the first communication channel and establishes a second communication channel between the cloud-based gateway and the service domain requested by the service agent.


