Rendezvous Gateway Firewall Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for external users to access services behind a firewall are inefficient, unsecure, and increase the attackable surface of the firewall, as they often require separate external infrastructure and special tunnel configurations that can render secure domains vulnerable to malware or hacking.
Innovation Solution
A network security system utilizing rendezvous gateway (RG) and rendezvous agent (RA) modules, which facilitate secure access by establishing a full connection between external clients and applications within a secure domain through synchronized messages and handshakes, authenticating users and maintaining security while allowing external access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a special tunnel is used to allow external client access to services behind a firewall, then connectivity is established, but the secure domain becomes vulnerable to malware or hacking
Solution Approach 1:
The patent introduces a tunnel broker as an intermediary component that mediates between external clients and the secure domain. The tunnel broker establishes tunnels on behalf of external clients to services behind the firewall, rather than allowing direct client-to-service tunnel connections. This intermediary architecture maintains security by preventing external clients from directly accessing the secure domain while still enabling the required connectivity through controlled tunnel establishment.
2Ease of operation
If tunneling software is required for external clients to use the firewall, then access control is enforced, but the attackable surface of the firewall increases
Solution Approach 1:
The patent extracts the tunnel establishment functionality from the firewall itself and relocates it to a tunnel broker component. By taking out the tunneling software requirements from the firewall, the firewall no longer needs to directly handle or understand tunnel protocols, thereby reducing its attackable surface while maintaining access control capabilities through the brokered tunnel mechanism.
3Adaptability or versatility
If separate external infrastructure is created for each application, then application-specific access is enabled, but system complexity and maintenance burden increase
Solution Approach 1:
The tunnel broker serves as a universal infrastructure that handles tunnel establishment for multiple different applications and services behind the firewall. Instead of requiring separate external infrastructure for each application, the single tunnel broker provides multi-functional tunneling capabilities, reducing overall system complexity and maintenance burden while still enabling application-specific access control.
Data Source
AI summary
Methods, non-transitory computer readable media, rendezvous gateway (RG) apparatuses, and network security systems that send an RG synchronization message (SYN) to an application in a secure domain following receipt, from a client, of a client SYN comprising an indication of the application. A rendezvous agent (RA) SYN is received, via a firewall coupled to the security domain and in response to the RG SYN, from an RA in the secure domain. A first RG synchronization-acknowledgement message (SYN+ACK) is sent to the client in response to the client SYN. A second RG SYN+ACK is sent, via the firewall, to the RA in response to the RA SYN. The RA is notified of receipt of a client acknowledgement message (ACK) from the client. An RA ACK is received, from the RA and via the firewall, in response to the notification, to thereby establish a full connection between the client and the application.


