Identity-Aware Filtering Proxy for Virtual Network Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual networks face challenges in determining whether devices accessing remote network resources are authorized, often requiring encryption to be compromised, which violates security and is costly and unreliable, especially when managing multiple endpoints.
Innovation Solution
Implementing an identity-aware filtering proxy that maintains encryption integrity by acting as a valid TLS termination point, using valid certificates, and evaluating API calls without cracking encryption, allowing authorized access while preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the virtual network compromises encryption security to inspect API calls, then it can determine whether the account is authorized to access resources, but this violates security principles and is costly and unreliable
Solution Approach 1:
The patent introduces a proxy server as an intermediary component between the client device and the remote network resources. This proxy server acts as a trusted mediator that can inspect API calls without compromising the encryption security of the direct communication channel. The proxy server receives, evaluates, and forwards API calls, enabling authorization verification while maintaining the integrity of encrypted communications.
2Reliability
If multiple proxies are deployed to manage multiple endpoints, then authorization verification capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent designs the proxy server with universal functionality that enables it to handle API calls to multiple different remote network resources through a single endpoint. The proxy server evaluates API calls based on the account information embedded in the calls themselves, without requiring separate proxies for each resource. This multi-functional approach reduces infrastructure complexity while maintaining comprehensive authorization verification capability.
Data Source
AI summary
Devices and methods are provided for using an identity-aware proxy to filter transmissions for virtual networks. The device may receive an encrypted application programming interface (API) call from a second device, wherein the encrypted API call is associated with a remote network resource, and wherein the device is included in a remote network which includes the remote network resource. The device may determine, based on the encrypted API call, an account associated with the remote network resource. The device may determine that the account is not authorized to access the remote network resource using the remote network. The device may send an error notification to the second device.


