Hybrid Cloud Gateway Outbound Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid cloud environments, establishing secure connectivity between on-premises data centers and public clouds is challenging due to security risks associated with opening non-standard ports in firewalls, which is not an accepted security practice.

Innovation Solution

A system and method for secure hybrid cloud connectivity is implemented by launching a public cloud gateway appliance in the public cloud, configuring it with security information from the on-premises appliance, and establishing a communication channel using an outbound port, ensuring secure communication without requiring non-standard port openings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If non-standard ports are opened in the on-premises firewall to allow access to on-prem resources, then connectivity between public cloud applications and on-premises services is improved, but security risk increases

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of opening inbound ports in the on-premises firewall to allow cloud applications to access on-prem resources, the solution inverts the connection direction by having the on-premises appliance initiate outbound connections to the public cloud. This reversal allows connectivity while maintaining firewall security policies that block inbound connections from untrusted networks.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a cloud gateway appliance as an intermediary component deployed in the public cloud. This gateway serves as a secure entry point that receives outbound connections from the on-premises appliance and forwards traffic to cloud applications. The gateway acts as a mediator that enables connectivity without requiring the on-premises firewall to open inbound ports, thus maintaining security while achieving the desired connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If standard firewall security policies are maintained to block inbound connections, then security is improved, but connectivity from public cloud to on-premises resources deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconnectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent resolves this contradiction by inverting the traditional connection model. Rather than allowing inbound connections from the cloud to the on-premises network (which would compromise security), the on-premises appliance initiates outbound connections to the cloud gateway. This inversion maintains strict inbound connection blocking while enabling necessary connectivity through outbound connections that are already permitted by security policies.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The solution employs preliminary action by pre-establishing a trusted communication channel between the on-premises appliance and the cloud gateway appliance. Security credentials and configurations are exchanged and validated before actual business traffic flows. This preliminary setup creates a secure foundation that enables subsequent connectivity without requiring changes to existing firewall security policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11689522B2Method and apparatus for secure hybrid cloud connectivity
Publication Date: 2023.06.27 VMWARE INC
  • US11689522B2 patent drawing
  • US11689522B2 patent drawing
  • US11689522B2 patent drawing

AI summary

System and computer-implemented method for secure hybrid cloud connectivity between an application in a public cloud service and an on-premises service supported by an on-premises appliance includes launching a public cloud gateway appliance in the public cloud service. The public cloud gateway appliance is configured with security information associated with the on-premises appliance. The on-premises appliance is provided with contact information associated with the public cloud gateway appliance. A communication channel is established, using an outbound port, from the on-premises appliance to the public cloud gateway appliance that is secured based on the security information associated with the on-premises appliance and the contact information associated with the public cloud gateway appliance.