Storage Computer Initiates Network Connection to Client

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network configurations that prioritize security by restricting initiation of connections from within restricted networks hinder efficient data exchange and development processes, such as testing and development, due to limitations in communication protocols and security policies, leading to performance issues and potential security breaches.

Innovation Solution

A method and system that enable a storage computer to initiate a network connection with a client computer, while disabling the client computer's ability to initiate the connection, allowing secure and efficient access to resources within the restricted network, using connection-oriented protocols and generic network file system protocols to facilitate data exchange without violating security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computers are protected by firewalls and antivirus software with restricted network connections, then security level is improved, but communication flexibility and data exchange efficiency deteriorate

Engineering Contradiction:
Improvesecurity levelVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of allowing the client computer to initiate connections to the storage computer (traditional approach), the invention inverts the connection initiation direction: the storage computer initiates the connection to the client computer. This reversal enables resource access while maintaining firewall restrictions, as the connection appears to originate from the restricted network side rather than external side.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention introduces a file system interface and protocol layer as an intermediary between the client computer and storage computer. This intermediary layer (including the file system driver and network file system protocol implementation) translates resource access requests into connection-oriented protocol communications, enabling secure resource sharing through the firewall without direct peer-to-peer connection initiation from the client.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If only authorized users outside the restricted network can connect to computers within the restricted network, then information leakage is prevented, but legitimate resource access from within the restricted network is hampered

Engineering Contradiction:
Improveinformation securityVSAvoidresource access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention reverses the traditional client-server connection model: instead of the client (outside restricted network) initiating connection to the server (inside restricted network), the storage computer (acting as server) initiates connection to the client computer. This allows resources to be accessible from within the restricted network while maintaining the security posture that only authorized external users can be contacted.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The storage computer autonomously initiates connections to client computers to provide resource access, rather than waiting for external requests. This self-service approach enables the storage computer to actively serve resources to authorized clients within the restricted network while maintaining firewall security policies.

Inventive Principle:
Principle #25Self-service

3Reliability

If connection-oriented protocols are used for secure communication, then security is improved, but communication efficiency and development process speed deteriorate

Engineering Contradiction:
Improvecommunication securityVSAvoiddata exchange efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention establishes persistent connection-oriented communication channels between the storage computer and client computers, maintaining continuous useful action for resource access. Once the connection is established by the storage computer, resource data exchange can proceed efficiently over this persistent channel without repeated connection setup overhead, balancing security with communication efficiency.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10218790B2Providing access to a resource for a computer from within a restricted network
Publication Date: 2019.02.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10218790B2 patent drawing
  • US10218790B2 patent drawing

AI summary

Disclosed are systems, methods, and machine readable storage media that cause a storage computer and a client computer to perform a method of providing access to one or more resources on the storage computer for the client computer. The storage computer is operable for initiation of a network connection between the client computer and the storage computer. Initiation of the network connection between the client computer and the storage computer by the storage computer is enabled, and initiation of the network connection between the client computer and the storage computer by the client computer is disabled. The client computer and the storage computer are operable for maintaining the network connection between the client computer and the storage computer.