Transparent Proxy SSL Inspection for Multi-App IP Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security mechanisms in web software architecture fail to provide granular control over network security policies for multiple HTTP/S web applications sharing the same IP address, as they lack the ability to assign separate SSL certificates based on Fully Qualified Domain Names (FQDNs), resulting in all web applications being treated equally without distinct security controls.

Innovation Solution

Implementing a true transparent proxy system that publishes each real server on a FQDN associated with a common IP address, assigns and stores SSL inspection certificates for each FQDN, and securely forwards network traffic to web site destinations, allowing for individual security policy management of each web application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional security mechanisms verify a single SSL certificate for the server IP address, then the security verification process is simple, but granular control over network security policies for multiple web applications is lost

Engineering Contradiction:
Improvesecurity verification processVSAvoidgranular control over network security policies
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the SSL certificate verification process by introducing FQDN-based certificate assignment. Instead of a single certificate for the IP address, multiple certificates are assigned to different FQDNs that map to the same IP. This allows each web application to have its own certificate and security policy while maintaining simple verification processes for each individual application.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to SSL certificate verification by introducing the FQDN layer between the IP address and the web application. This dimensional addition allows the system to maintain simple IP-based routing while implementing granular FQDN-based security policies and certificate verification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If all web applications share the same IP address and SSL certificate, then network configuration is simplified, but distinct security controls for individual applications cannot be implemented

Engineering Contradiction:
Improvenetwork configurationVSAvoiddistinct security controls
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments security controls by associating different SSL certificates with different FQDNs that resolve to the same IP address. This segmentation allows each web application to have its own security policy and certificate while sharing the common IP address infrastructure, thus maintaining simple network configuration while enabling distinct security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing each FQDN to have its own SSL certificate and security policy characteristics. This means that while the network infrastructure (IP address) remains uniform and simple, the security properties can be locally customized for each web application based on its specific FQDN.

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If a single SSL certificate is used for multiple web applications, then certificate management is easier, but security policy granularity and application-specific security requirements cannot be met

Engineering Contradiction:
Improvecertificate managementVSAvoidapplication-specific security requirements
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments certificate management by organizing certificates according to FQDNs rather than IP addresses. This segmentation allows multiple certificates to be managed systematically, each associated with a specific FQDN. The system maintains ease of management through automated FQDN-to-certificate mapping while enabling application-specific security requirements through FQDN-based certificate selection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11153280B1True transparent proxy to support multiple HTTP/S web applications on same IP and port on a data communication network
Publication Date: 2021.10.19 FORTINET INC
  • US11153280B1 patent drawing
  • US11153280B1 patent drawing
  • US11153280B1 patent drawing

AI summary

A true transparent proxy for a web application firewall is provided. Granular network security policies are applied on a per web application basis using unique SSL inspection certificates for web applications sharing a common IP address.