Proxy Server Secure Replication Across Public Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure replication partnership between geographically remote storage nodes across a public network is challenging, especially when the nodes are owned by different entities, as it requires setting up secure communication channels and managing network infrastructure, which can be complex and requires specific devices like firewalls or VPNs.
Innovation Solution
A web portal and proxy server system is used to set up and manage replication partnerships between local and remote storage nodes, employing SSH tunnels for secure data transfer, where the proxy server acts as a network endpoint, and the web portal orchestrates the setup, selecting appropriate data centers and configuring secure communication channels without the need for special devices like firewalls or VPNs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure communication channels are established between geographically remote storage nodes over a public network, then data security is improved, but device complexity and setup difficulty increase due to requiring firewalls or VPNs
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that mediates secure communication between storage nodes. The proxy server establishes secure tunnels and manages authentication, eliminating the need for complex firewall or VPN configurations at each storage node. This intermediary approach maintains data security while significantly reducing device complexity and setup difficulty.
2Reliability
If secure communication channels are established between geographically remote storage nodes, then data security is improved, but ease of operation deteriorates due to complex setup requirements
Solution Approach 1:
The system implements self-service automation where the proxy server automatically performs authentication, establishes secure tunnels, and configures communication parameters without requiring manual intervention. The storage nodes automatically register with the proxy server and receive configured connection parameters, eliminating complex manual setup procedures while maintaining robust security.
3Adaptability or versatility
If replication partnerships are established between storage nodes owned by different entities, then adaptability is improved, but device complexity increases due to need for specialized network devices
Solution Approach 1:
The proxy server is designed as a universal platform that handles multiple functions including authentication, tunnel establishment, encryption management, and replication coordination. This multi-functional design enables storage nodes from different entities to establish replication partnerships without requiring entity-specific network infrastructure, thereby improving adaptability while reducing device complexity.
Data Source
AI summary
A technique includes causing an agent device to setup a replication partnership between a first storage node and a second storage. Causing the agent device to setup the replication partnership includes configuring a proxy server that is associated with the second storage node to establish a secure communication channel for the replication partnership over a public network. Configuring the proxy server includes storing in the proxy server credentials for authenticating the first storage node to use the secure communication channel; and establishing port translations to be used in the secure communication channel in communicating replication data between the first storage node and the second storage node. Causing the agent device to setup the replication partnership may also include communicating replication partnership information to the second node.


