Hybrid Cloud File Sharing Appliance with Secure Relay Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional file sharing and synchronization services for small-to-medium-sized businesses (SMBs) expose them to significant data security risks due to the requirement for a public IP address, which acts as an unsecure access hole in the firewall, compromising the integrity of their IT infrastructure.
Innovation Solution
Integration of file sharing and synchronization (FSS) functionality with backup management and storage (BMS) in a single appliance deployed within a private and trusted LAN, enabling secure access for remote users without exposing the LAN to security risks through the use of a relay server cluster and secure communication protocols like SSH tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional file sharing and synchronization services are deployed with public IP address, then remote access capability is improved, but network security deteriorates due to creating an unsecure access hole in the firewall
Solution Approach 1:
The patent introduces a relay server as an intermediary component that mediates between remote clients and the private LAN. The relay server establishes secure SSH tunnel connections to the private LAN, allowing remote file sharing and synchronization operations without requiring public IP address exposure. This intermediary approach enables remote access while maintaining firewall integrity and network security.
2Object-affected harmful factors
If FSS services are isolated within private LAN without public access, then network security is improved, but remote user accessibility deteriorates
Solution Approach 1:
The relay server acts as a mediator that enables remote users to access FSS services within the private LAN without compromising security. By establishing authenticated SSH tunnel connections, the relay server provides a secure gateway that maintains LAN isolation while enabling remote functionality.
Solution Approach 2:
The relay server provides multi-functional capabilities by supporting multiple simultaneous connections to different private LANs, handling various file sharing and synchronization operations, and providing both authentication and data transmission functions through a single unified service architecture.
3Adaptability or versatility
If separate appliances are used for FSS and BMS, then functional versatility is improved, but device complexity and deployment cost deteriorates
Solution Approach 1:
The patent combines file sharing and synchronization (FSS) services with backup management and storage (BMS) services into a single integrated appliance deployed within the private LAN. This consolidation reduces deployment complexity, lowers hardware costs, and simplifies management while maintaining both functional capabilities through a unified system architecture.
Solution Approach 2:
The integrated appliance provides multi-functional capabilities by simultaneously supporting both FSS operations (file sharing, synchronization, collaboration) and BMS operations (backup, restore, disaster recovery) within a single device, eliminating the need for separate specialized appliances.
Data Source
AI summary
Integrated File Sharing and Synchronization (FSS) and Backup Management and Storage (BMS) in a network appliance deployed behind a firewall and within a private trusted Local Area Network (LAN). The appliance processes backup image files of a LAN server's file system to generate fully constructed backup recovery points for the LAN server. Logical blocks for backup image files and associated recovery points may be stored locally on the appliance and redundantly in a trusted cloud domain, and a hypervisor on the appliance provides virtualization of the LAN server based on backup recovery points. A relay server cluster in the cloud facilitates reliable and secure access to the FSS services by remote client devices beyond the firewall, without changing fire wall rules, by employing HTTPS between remote client devices and the relay server cluster, and Secure Shell (SSH) tunneling between the cluster and the appliance behind the firewall.


