Secure Middlebox Management via Gateway Protocol Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of network middleboxes in cloud-based virtualized computing systems is challenging due to security restrictions that prevent external access to management networks, making it difficult for IT administrators to manage and diagnose middleboxes, especially when they are provided by third-party vendors with unique protocols and APIs.

Innovation Solution

A method that involves receiving management packets through a secure channel, translating them to the appropriate protocol or API of the network middlebox, and transmitting them securely, using a gateway with a secure router daemon to authenticate and forward management requests, thereby balancing security and manageability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If middleboxes are connected to management network for easy management, then manageability is improved, but security is worsened due to potential unauthorized access

Engineering Contradiction:
ImprovemanageabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the management network and middleboxes. The gateway receives management packets from the management network, translates them to the appropriate protocols, and forwards them to middleboxes. This mediator allows management functionality while preventing direct access to middleboxes, thus maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network access into two distinct paths: a management network for control operations and a data network for middlebox communication. By separating these functions and using protocol translation at the gateway, the system enables management capabilities while maintaining security isolation between networks.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple protocols and APIs are supported for third-party middleboxes, then adaptability is improved, but device complexity is worsened

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway device is designed with universal protocol translation capabilities, supporting multiple protocols and APIs (such as SNMP, NETCONF, RESTful APIs) through a single unified interface. This allows the gateway to adapt to different third-party middleboxes without requiring separate management systems for each protocol type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway acts as a protocol translation intermediary, converting standardized management packets from the management network into device-specific protocols for various middleboxes. This mediator approach enables broad adaptability while keeping the management network side simple and standardized.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If management network is separated from data network for security, then security is improved, but manageability is worsened due to inaccessible middleboxes

Engineering Contradiction:
Improvesecurity protectionVSAvoidaccessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The gateway serves as a secure intermediary that bridges the separated management network and data network. It receives authenticated management packets from the management network, translates protocols as needed, and forwards them to middleboxes on the data network. This maintains security isolation while enabling management access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds a translation dimension between networks by implementing protocol conversion at the gateway. This allows management operations to traverse from the management network through the gateway to reach middleboxes on the data network, effectively bridging the separation without compromising security boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10608959B2Securely managing and diagnosing network middleboxes
Publication Date: 2020.03.31 VMWARE INC
  • US10608959B2 patent drawing
  • US10608959B2 patent drawing
  • US10608959B2 patent drawing

AI summary

The disclosure provides an approach for managing and diagnosing middleboxes in a cloud computing system. In one embodiment, a network operations center, that is located remote to a virtualized cloud computing system and communicates with the cloud computing system via a wide area network, controls network middleboxes in the cloud computing system through a secure routing module inside a gateway of the cloud computing system. The secure routing module is configured to receive, from an authenticated management application and via a secure communication channel, packets intended for managing network middleboxes. In turn, the secure routing module establishes secure communication channels with the target middleboxes, translates the identified packets to protocols and/or application programming interfaces (APIs) of the target middleboxes, and transmits the translated packets to the target middleboxes.