Identity-Aware Filtering Proxy for Virtual Network Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual networks face challenges in determining whether devices accessing remote network resources are authorized, often requiring encryption to be compromised, which violates security and is costly and unreliable, especially when managing multiple endpoints.

Innovation Solution

Implementing an identity-aware filtering proxy that maintains encryption integrity by acting as a valid TLS termination point, using valid certificates, and evaluating API calls without cracking encryption, allowing authorized access while preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the virtual network compromises encryption security to inspect API calls, then it can determine whether the account is authorized to access resources, but this violates security principles and is costly and unreliable

Engineering Contradiction:
Improveauthorization verification reliabilityVSAvoidsecurity violation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy server as an intermediary component between the client device and the remote network resources. This proxy server acts as a trusted mediator that can inspect API calls without compromising the encryption security of the direct communication channel. The proxy server receives, evaluates, and forwards API calls, enabling authorization verification while maintaining the integrity of encrypted communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple proxies are deployed to manage multiple endpoints, then authorization verification capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthorization verification capabilityVSAvoidproxy infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the proxy server with universal functionality that enables it to handle API calls to multiple different remote network resources through a single endpoint. The proxy server evaluates API calls based on the account information embedded in the calls themselves, without requiring separate proxies for each resource. This multi-functional approach reduces infrastructure complexity while maintaining comprehensive authorization verification capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11516253B1Identity-aware filtering proxy for virtual networks
Publication Date: 2022.11.29 AMAZON TECH INC
  • US11516253B1 patent drawing
  • US11516253B1 patent drawing
  • US11516253B1 patent drawing

AI summary

Devices and methods are provided for using an identity-aware proxy to filter transmissions for virtual networks. The device may receive an encrypted application programming interface (API) call from a second device, wherein the encrypted API call is associated with a remote network resource, and wherein the device is included in a remote network which includes the remote network resource. The device may determine, based on the encrypted API call, an account associated with the remote network resource. The device may determine that the account is not authorized to access the remote network resource using the remote network. The device may send an error notification to the second device.