Proxy System for Secure Network Connection Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As computing systems grow, managing the increasing number of connections between clients and remote computing arrangements over public networks becomes inefficient, requiring more effective methods to establish and manage secure connections.

Innovation Solution

A proxy system that automatically determines the need for and establishes secure connections, such as VPN sessions, between computing devices and computing arrangements, using virtualized computing resources and dynamic VPN activation to manage multiple segregated environments and connections efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple secure connections are established manually for each client to computing arrangement, then connection security is maintained, but system complexity and management overhead increase significantly

Engineering Contradiction:
Improveconnection securityVSAvoidconnection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A proxy system is introduced as an intermediary between clients and computing arrangements. The proxy receives connection requests, determines whether secure connections exist, and establishes new connections when needed. This intermediary manages the complexity of multiple secure connections centrally, allowing individual clients to connect without manually managing their own secure connection infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The proxy system automatically determines whether a secure connection exists between the client and computing arrangement, and autonomously establishes new connections when needed. This self-service capability eliminates manual intervention for connection management, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If secure connections are established for every client request, then connection security is ensured, but resource consumption and connection establishment time increase

Engineering Contradiction:
Improveconnection securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The proxy system checks whether a secure connection already exists before establishing a new one. By performing this preliminary check, the system avoids redundant connection establishment operations, saving computing resources and reducing connection establishment time while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Multiple clients can share the same secure connection to a computing arrangement through the proxy system. Instead of establishing separate secure connections for each client request, the proxy consolidates connection resources, allowing multiple clients to utilize existing secure connections when available, thereby reducing overall resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If manual connection management is used for scaling systems, then individual connection control is maintained, but management efficiency decreases as system size increases

Engineering Contradiction:
Improveconnection controlVSAvoidconnection management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The proxy system automatically manages connection establishment and termination based on client requests and existing connection states. This automation handles the increasing number of connections that arise with system scaling, maintaining ease of operation for individual clients while dramatically improving overall management efficiency through centralized automated control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10547597B2Secure network connections
Publication Date: 2020.01.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10547597B2 patent drawing
  • US10547597B2 patent drawing
  • US10547597B2 patent drawing

AI summary

A method and associated system for connecting a computing device to a computing arrangement. A message from the computing device is received. The message includes an address specifying the computing arrangement. The proxy system is a computer system. It is determined, based on the address, that a secure connection between the proxy system and the computing arrangement does not exist. The secure connection is dedicated for secure communication between the computing device and the computing arrangement. In response to the determining that the secure connection does not exist, a new secure connection is established between the proxy system and the computing arrangement.