Secure Proxy Service for Cross-Domain Cloud Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Accessing resources across different security domains in a cloud computing environment is challenging due to the security features and isolation between domains, making it difficult for users to share resources or data between domains without compromising security.
Innovation Solution
A cross-domain resource access system that uses a mapping identifier to proxy requests and responses across domains, maintaining high levels of privacy and security by routing traffic through private networks, thereby enabling asynchronous request/response models between domains with different security classifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features and isolation between domains are maintained, then domain security is improved, but resource accessibility across domains deteriorates
Solution Approach 1:
The patent implements a proxy service that acts as an intermediary between isolated security domains. The proxy receives requests from one domain, forwards them to resources in another domain, and returns responses, thereby enabling cross-domain resource access without compromising the security isolation. The proxy service mediates the interaction between domains with different security classifications, allowing controlled access while maintaining boundary integrity.
2Adaptability or versatility
If direct access between domains is allowed, then resource sharing is improved, but security compromise risk increases
Solution Approach 1:
The proxy service serves as a secure intermediary that enables resource sharing between domains without direct access. It forwards requests and responses between domains while maintaining security boundaries, allowing adaptable resource sharing across different security classifications without exposing domains to direct security risks.
Solution Approach 2:
The system segments cross-domain communication into distinct request and response paths handled by the proxy service. This segmentation allows resource sharing functionality to be decoupled from direct domain-to-domain connections, enabling versatility in resource access while containing security risks within isolated communication channels.
3Ease of operation
If public networks are used for cross-domain access, then network connectivity is improved, but security exposure increases
Solution Approach 1:
The proxy service acts as an intermediary that routes cross-domain traffic through private networks instead of public networks. It receives requests from one domain, forwards them through private network infrastructure to resources in another domain, and returns responses, thereby maintaining network connectivity while eliminating security exposure associated with public network traversal.
Data Source
AI summary
Cross domain resource access includes accessing resources in a first domain from a second domain. This may be performed using the methods, system, and devices described herein. This may include maintaining a mapping identifier for a user of a service provider based on user information. The service provider may provide first and second security domains for the user. The mapping identifier may be associated with an endpoint of a private cloud computing service of the first security domain. The may also include receiving, from the first security domain, a request associated with a resource of the second security domain, the request comprising the mapping identifier. This may also include routing the request from the first security domain to the second domain via a first private network link of the first security domain and a second private network link of the second security domain using a confidentiality controlled interface.


