Tunnel Service Server Firewall Traversal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in establishing a secure and efficient tunnel between a computing device and a tunnel service server, particularly in traversing firewalls while ensuring encrypted data transmission, especially for mobile devices accessing enterprise networks.
Innovation Solution
A system is implemented that includes a tunnel service server, relay servers, and signaling/service servers to establish a secure tunnel by encrypting application data, packaging it with source and destination addresses, and transmitting it through firewalls, with relay servers repackaging and decrypting data for mobile devices, ensuring secure and encrypted communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a virtual private network is established to allow remote access to corporate network resources, then secure communication is achieved, but ports must be opened in the firewall which reduces network security
Solution Approach 1:
The patent introduces a tunnel service server as an intermediary component that mediates between the mobile device and corporate network resources. Instead of opening firewall ports, the tunnel service server receives encrypted tunnel packets from mobile devices, decrypts them, and forwards the contained data packets to the appropriate corporate network resources. This intermediary approach maintains firewall security while enabling secure remote access.
2Object-affected harmful factors
If multiple firewalls are deployed to enhance network security, then network protection is improved, but the complexity of establishing secure tunnels increases
Solution Approach 1:
The mobile device autonomously establishes secure tunnels to the tunnel service server without requiring manual configuration or complex coordination with multiple firewalls. The device initiates the tunnel connection, and the tunnel service server automatically manages the decryption and forwarding processes. This self-service approach simplifies the overall system complexity while maintaining multiple firewall layers for enhanced security.
3Productivity
If direct peer-to-peer connection is established between mobile device and endpoint, then communication efficiency is improved, but the ability to traverse firewalls is reduced
Solution Approach 1:
The patent segments the communication process into two distinct parts: an encrypted tunnel channel for traversing firewalls and the actual data payload for efficient communication. The tunnel service server separates the encrypted tunnel packets from the contained data packets, allowing the outer encrypted layer to traverse firewalls while the inner data layer maintains communication efficiency. This segmentation enables both firewall traversal and efficient communication simultaneously.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure presents a system, method and apparatus herein enabling secure coupling of a computing device, such as a mobile device with an endpoint, such as an application server. The computing device can include any electronic device such as a computer, a server, an application server, a mobile device or tablet. The endpoint can be any electronic device as well that is located within an enterprise network. In at least one embodiment, the secure coupling of the mobile device with a computing device can include a security gateway server. In one example, the security gateway server can be a tunnel service server. In another embodiment, an application server can include a tunnel service module to provide the secure coupling with the mobile device.