Transparent Proxy SSL Inspection for Multi-App IP Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security mechanisms in web software architecture fail to provide granular control over network security policies for multiple HTTP/S web applications sharing the same IP address, as they lack the ability to assign separate SSL certificates based on Fully Qualified Domain Names (FQDNs), resulting in all web applications being treated equally without distinct security controls.
Innovation Solution
Implementing a true transparent proxy system that publishes each real server on a FQDN associated with a common IP address, assigns and stores SSL inspection certificates for each FQDN, and securely forwards network traffic to web site destinations, allowing for individual security policy management of each web application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional security mechanisms verify a single SSL certificate for the server IP address, then the security verification process is simple, but granular control over network security policies for multiple web applications is lost
Solution Approach 1:
The patent segments the SSL certificate verification process by introducing FQDN-based certificate assignment. Instead of a single certificate for the IP address, multiple certificates are assigned to different FQDNs that map to the same IP. This allows each web application to have its own certificate and security policy while maintaining simple verification processes for each individual application.
Solution Approach 2:
The patent adds a new dimension to SSL certificate verification by introducing the FQDN layer between the IP address and the web application. This dimensional addition allows the system to maintain simple IP-based routing while implementing granular FQDN-based security policies and certificate verification.
2Device complexity
If all web applications share the same IP address and SSL certificate, then network configuration is simplified, but distinct security controls for individual applications cannot be implemented
Solution Approach 1:
The patent segments security controls by associating different SSL certificates with different FQDNs that resolve to the same IP address. This segmentation allows each web application to have its own security policy and certificate while sharing the common IP address infrastructure, thus maintaining simple network configuration while enabling distinct security controls.
Solution Approach 2:
The patent applies local quality by allowing each FQDN to have its own SSL certificate and security policy characteristics. This means that while the network infrastructure (IP address) remains uniform and simple, the security properties can be locally customized for each web application based on its specific FQDN.
3Ease of manufacture
If a single SSL certificate is used for multiple web applications, then certificate management is easier, but security policy granularity and application-specific security requirements cannot be met
Solution Approach 1:
The patent segments certificate management by organizing certificates according to FQDNs rather than IP addresses. This segmentation allows multiple certificates to be managed systematically, each associated with a specific FQDN. The system maintains ease of management through automated FQDN-to-certificate mapping while enabling application-specific security requirements through FQDN-based certificate selection.
Data Source
AI summary
A true transparent proxy for a web application firewall is provided. Granular network security policies are applied on a per web application basis using unique SSL inspection certificates for web applications sharing a common IP address.


