Reverse-Tunnel Proxy for Secure Cloud Service Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud customers face challenges in economically optimizing the distribution of web services across non-homogeneous Cloud providers with dynamically changing cost models, managing security exposure, and replicating services with greater depth and functionality without exceeding the application workload cost, especially concerning SSL private key storage and compliance in public CSP environments.

Innovation Solution

Implementing a reverse-tunnel proxy in a cloud environment that automatically discovers the cloud environment, creates a secure connection without using public IP, and manages application traffic through a network traffic management system, allowing for load-balancing, secure key storage, and scalable service tiers across multiple CSPs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customers deploy services across multiple Cloud Service Providers to optimize pricing and reliability, then cost savings and redundancy are achieved, but the complexity of managing non-homogeneous Cloud resources with dynamically changing cost models increases

Engineering Contradiction:
ImproveredundancyVSAvoidcomplexity of managing non-homogeneous Cloud resources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a service mesh architecture with proxies and control planes as intermediaries between applications and Cloud Service Providers. These intermediaries abstract away the complexity of managing multiple non-homogeneous CSPs, handling service discovery, load balancing, and configuration management centrally, thereby enabling multi-CSP deployment without proportionally increasing operational complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The service mesh implements universal, standardized interfaces and protocols that work across different Cloud Service Providers. The proxy components and control planes provide multi-functional capabilities including service discovery, load balancing, security management, and configuration handling that operate consistently across heterogeneous CSP environments, reducing the need for CSP-specific management logic

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If customers use Public IP addresses for workload components in public CSP environments, then network connectivity is achieved, but security exposure and compliance risks increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The service mesh introduces proxy components as intermediaries that handle all external communications. These proxies act as secure entry/exit points that can enforce authentication, authorization, and encryption policies, allowing workloads to maintain network connectivity through the proxies rather than exposing Public IPs directly, thereby reducing security exposure while preserving connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts Public IP address requirements from individual workload components and consolidates them at the service mesh boundary. By removing direct Public IP exposure from workloads and handling all external traffic through controlled proxy interfaces, the solution maintains network connectivity while minimizing the attack surface and compliance risks associated with exposed Public IPs

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If customers replicate services with greater depth and functionality across Cloud providers, then service quality is improved, but the cost may exceed the application workload cost

Engineering Contradiction:
Improveservice qualityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The service mesh implements lightweight proxy copies at each service endpoint rather than replicating full service functionality across multiple Cloud providers. These proxy copies handle service discovery, traffic routing, and local caching, enabling high availability and service quality through intelligent traffic distribution while avoiding the high costs of fully replicating service functionality across multiple CSPs

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11159490B2Methods and devices for service-discovering reverse-tunnel proxy and tunnel service center
Publication Date: 2021.10.26 F5 NETWORKS INC
  • US11159490B2 patent drawing
  • US11159490B2 patent drawing
  • US11159490B2 patent drawing

AI summary

Methods, non-transitory computer readable media, network traffic management apparatuses, and network traffic management systems that utilize a reverse tunnel proxy in a cloud environment. The reverse tunnel proxy in a cloud environment automatically discovers its environment and creates an appropriate tunnel without using a public IP. The reverse tunnel proxy in a cloud environment utilizes an outgoing connection along with an initialization and channelization to connect to the cloud and accepts an incoming connection in response. In embodiments, a cloud initiates a connection and a tunnel is created without need for additional IP addresses. In embodiments, the reverse tunnel proxy in a cloud environment connects to a client as a server and a private key is stored at a server side without pushing private keys into a public environment.