Generic Proxy Endpoints for Cloud Native Firewall Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cloud-native applications face challenges in accessing and communicating with services located behind firewalls, particularly in private data centers, where there is no generic way to access these services from outside without creating firewall exceptions, posing security risks due to potential intrusion threats.

Innovation Solution

The implementation of a generic proxying system that creates communication tunnels using a Platform-as-a-Service (PaaS) Management Portal, which dynamically generates and manages proxy endpoints and tunnel connections across various tunneling protocols, enabling flexible access to services behind firewalls without the need for dedicated endpoints or protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firewall exceptions are created to access services from outside, then accessibility is improved, but security is worsened due to potential intrusion threats

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy service as an intermediary component that enables external access to services behind firewalls without creating direct exceptions. The proxy establishes secure tunnel connections through the firewall using established protocols (SSH, HTTPS, etc.), acting as a mediator between external clients and internal services. This resolves the contradiction by maintaining firewall security while enabling accessibility through the intermediary proxy mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If dedicated endpoints are created for each service, then accessibility is improved, but device complexity increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidendpoint management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal proxy service that can access multiple different services through a single generic interface. Instead of creating dedicated endpoints for each service, the proxy service provides a unified mechanism that works across various services by dynamically establishing appropriate tunnel connections. This multi-functional approach reduces complexity while maintaining accessibility to diverse services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs dynamic endpoint creation where the proxy service automatically generates and manages endpoints on-demand based on service requirements. Endpoints are dynamically created, monitored, and removed as needed, rather than being statically configured. This dynamic approach simplifies management while ensuring accessibility, as the system adapts to changing service needs automatically.

Inventive Principle:
Principle #15Dynamics

3Reliability

If tunnel connections are established manually, then reliability is improved, but productivity is worsened due to manual configuration time

Engineering Contradiction:
Improveconnection stabilityVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service automation where the proxy service automatically establishes, monitors, and manages tunnel connections without manual intervention. The system autonomously creates endpoints, configures connections, and handles lifecycle management based on service requirements. This self-service capability maintains connection reliability through automated monitoring while dramatically improving productivity by eliminating manual configuration steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring the proxy service infrastructure and establishing connection templates before actual service deployment. The system prepares endpoint configurations and connection parameters in advance, enabling rapid deployment of tunnel connections when services are instantiated. This preliminary preparation ensures reliable connections while accelerating deployment speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11736585B2Generic proxy endpoints using protocol tunnels including life cycle management and examples for distributed cloud native services and applications
Publication Date: 2023.08.22 NUTANIX INC
  • US11736585B2 patent drawing
  • US11736585B2 patent drawing
  • US11736585B2 patent drawing

AI summary

Applications or Agents or Administrators can communicate with services and/or applications at hosted and/or remote locations via proxy service or application endpoints. Proxy Services described here may, in examples, manage the life cycle of communication channels, or tunnels to ensure guaranteed access to hosted services and applications regardless of their location. Examples of proxy services may create one or more tunnels, each in accordance with a particular tunneling protocol. The tunneling protocol used may be selected in accordance with a request, including information parameters—in this manner, proxy services described herein may be quite flexible in supporting tunneling connections to multiple and variable types of services and tunneling protocols.