Reverse Access Architecture for Secure DMZ-LAN Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems with DMZs face challenges such as high costs and vulnerabilities due to data duplication, management complexity, and susceptibility to hacking, which compromise the security of internal networks and data integrity in the LAN.
Innovation Solution
A system that secures data on the LAN by establishing a connection binder between the DMZ and LAN servers, allowing seamless communication without requiring administrative management on the LAN server, using a LAN controller to manage client requests and a DMZ stack pool service to route requests securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is duplicated on both DMZ and LAN computers, then service availability is improved, but cost and management complexity increase
Solution Approach 1:
The patent merges the data storage function into a single location (LAN computer) while maintaining service availability through virtualization. The virtual machine on the LAN computer provides services to both DMZ and LAN, eliminating the need for physical data duplication across multiple computers.
Solution Approach 2:
The patent creates a virtual copy of the data access interface through virtualization. Instead of copying physical data to multiple locations, a virtual machine interface is created that allows multiple access points to the single data source, reducing management complexity while maintaining availability.
2Reliability
If data is duplicated on both DMZ and LAN computers, then service availability is improved, but licensing costs increase
Solution Approach 1:
The patent consolidates data storage to a single LAN computer, which eliminates the need for multiple software licenses that would be required if data were duplicated across multiple DMZ and LAN computers. This merging approach reduces the quantity of licensed software instances while maintaining service availability.
3Adaptability or versatility
If DMZ interfaces with external systems, then communication capability is improved, but vulnerability to hacking increases
Solution Approach 1:
The patent introduces a virtual machine as an intermediary between the external DMZ interface and the internal LAN data. This virtual layer acts as a mediator that allows communication capability to external systems while isolating the actual data from direct exposure to hacking risks.
Solution Approach 2:
The patent segments the system into distinct virtual and physical layers. The DMZ interface operates in a virtualized environment that is logically separated from the physical data storage on the LAN computer, creating security zones that reduce vulnerability while maintaining communication capability.
4Reliability
If administrative management is required on LAN server, then security control is improved, but operational complexity increases
Solution Approach 1:
The patent implements self-service security control through the virtual machine architecture. The virtual machine on the LAN computer automatically manages security protocols and access control, reducing the need for manual administrative intervention while maintaining strong security control.
Data Source
AI summary
A System that provides a secured connection between servers on the LAN and clients on the WAN comprises the LAN (which includes LAN Server and LAN Controller) and the DMZ (which includes DMZ Server and DMZ Stack Pool Service). Wherein the Client Request reaches the DMZ Server it stores it in the DMZ Stack Pool Service and the LAN Controller establishes outbound TCP based connection to the DMZ Stack Pool Service that passes the Client Connection Information to the LAN Server via the LAN Controller. Then the LAN Server then generates a connection between the Service and DMZ Server.
