Reverse-Tunnel Proxy for Secure Cloud Service Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud customers face challenges in economically optimizing the distribution of web services across non-homogeneous Cloud providers with dynamically changing cost models, managing security exposure, and replicating services with greater depth and functionality without exceeding the application workload cost, especially concerning SSL private key storage and compliance in public CSP environments.
Innovation Solution
Implementing a reverse-tunnel proxy in a cloud environment that automatically discovers the cloud environment, creates a secure connection without using public IP, and manages application traffic through a network traffic management system, allowing for load-balancing, secure key storage, and scalable service tiers across multiple CSPs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If customers deploy services across multiple Cloud Service Providers to optimize pricing and reliability, then cost savings and redundancy are achieved, but the complexity of managing non-homogeneous Cloud resources with dynamically changing cost models increases
Solution Approach 1:
The patent introduces a service mesh architecture with proxies and control planes as intermediaries between applications and Cloud Service Providers. These intermediaries abstract away the complexity of managing multiple non-homogeneous CSPs, handling service discovery, load balancing, and configuration management centrally, thereby enabling multi-CSP deployment without proportionally increasing operational complexity
Solution Approach 2:
The service mesh implements universal, standardized interfaces and protocols that work across different Cloud Service Providers. The proxy components and control planes provide multi-functional capabilities including service discovery, load balancing, security management, and configuration handling that operate consistently across heterogeneous CSP environments, reducing the need for CSP-specific management logic
2Ease of operation
If customers use Public IP addresses for workload components in public CSP environments, then network connectivity is achieved, but security exposure and compliance risks increase
Solution Approach 1:
The service mesh introduces proxy components as intermediaries that handle all external communications. These proxies act as secure entry/exit points that can enforce authentication, authorization, and encryption policies, allowing workloads to maintain network connectivity through the proxies rather than exposing Public IPs directly, thereby reducing security exposure while preserving connectivity
Solution Approach 2:
The patent extracts Public IP address requirements from individual workload components and consolidates them at the service mesh boundary. By removing direct Public IP exposure from workloads and handling all external traffic through controlled proxy interfaces, the solution maintains network connectivity while minimizing the attack surface and compliance risks associated with exposed Public IPs
3Reliability
If customers replicate services with greater depth and functionality across Cloud providers, then service quality is improved, but the cost may exceed the application workload cost
Solution Approach 1:
The service mesh implements lightweight proxy copies at each service endpoint rather than replicating full service functionality across multiple Cloud providers. These proxy copies handle service discovery, traffic routing, and local caching, enabling high availability and service quality through intelligent traffic distribution while avoiding the high costs of fully replicating service functionality across multiple CSPs
Data Source
AI summary
Methods, non-transitory computer readable media, network traffic management apparatuses, and network traffic management systems that utilize a reverse tunnel proxy in a cloud environment. The reverse tunnel proxy in a cloud environment automatically discovers its environment and creates an appropriate tunnel without using a public IP. The reverse tunnel proxy in a cloud environment utilizes an outgoing connection along with an initialization and channelization to connect to the cloud and accepts an incoming connection in response. In embodiments, a cloud initiates a connection and a tunnel is created without need for additional IP addresses. In embodiments, the reverse tunnel proxy in a cloud environment connects to a client as a server and a private key is stored at a server side without pushing private keys into a public environment.


