Rendezvous Gateway Firewall Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for external users to access services behind a firewall are inefficient, unsecure, and increase the attackable surface of the firewall, as they often require separate external infrastructure and special tunnel configurations that can render secure domains vulnerable to malware or hacking.

Innovation Solution

A network security system utilizing rendezvous gateway (RG) and rendezvous agent (RA) modules, which facilitate secure access by establishing a full connection between external clients and applications within a secure domain through synchronized messages and handshakes, authenticating users and maintaining security while allowing external access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a special tunnel is used to allow external client access to services behind a firewall, then connectivity is established, but the secure domain becomes vulnerable to malware or hacking

Engineering Contradiction:
Improveexternal client accessVSAvoidsecure domain security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a tunnel broker as an intermediary component that mediates between external clients and the secure domain. The tunnel broker establishes tunnels on behalf of external clients to services behind the firewall, rather than allowing direct client-to-service tunnel connections. This intermediary architecture maintains security by preventing external clients from directly accessing the secure domain while still enabling the required connectivity through controlled tunnel establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If tunneling software is required for external clients to use the firewall, then access control is enforced, but the attackable surface of the firewall increases

Engineering Contradiction:
Improvefirewall access controlVSAvoidfirewall attackable surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the tunnel establishment functionality from the firewall itself and relocates it to a tunnel broker component. By taking out the tunneling software requirements from the firewall, the firewall no longer needs to directly handle or understand tunnel protocols, thereby reducing its attackable surface while maintaining access control capabilities through the brokered tunnel mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If separate external infrastructure is created for each application, then application-specific access is enabled, but system complexity and maintenance burden increase

Engineering Contradiction:
Improveapplication-specific accessVSAvoidexternal infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The tunnel broker serves as a universal infrastructure that handles tunnel establishment for multiple different applications and services behind the firewall. Instead of requiring separate external infrastructure for each application, the single tunnel broker provides multi-functional tunneling capabilities, reducing overall system complexity and maintenance burden while still enabling application-specific access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10958625B1Methods for secure access to services behind a firewall and devices thereof
Publication Date: 2021.03.23 F5 NETWORKS INC
  • US10958625B1 patent drawing
  • US10958625B1 patent drawing
  • US10958625B1 patent drawing

AI summary

Methods, non-transitory computer readable media, rendezvous gateway (RG) apparatuses, and network security systems that send an RG synchronization message (SYN) to an application in a secure domain following receipt, from a client, of a client SYN comprising an indication of the application. A rendezvous agent (RA) SYN is received, via a firewall coupled to the security domain and in response to the RG SYN, from an RA in the secure domain. A first RG synchronization-acknowledgement message (SYN+ACK) is sent to the client in response to the client SYN. A second RG SYN+ACK is sent, via the firewall, to the RA in response to the RA SYN. The RA is notified of receipt of a client acknowledgement message (ACK) from the client. An RA ACK is received, from the RA and via the firewall, in response to the notification, to thereby establish a full connection between the client and the application.