Virtualized Peer-to-Peer Proxy for Remote Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate IT departments face challenges in enforcing uniform content access policies on remote employees working outside the corporate intranet, as they may bypass proxy server restrictions when directly connected to the internet, making it difficult to monitor and enforce corporate policies.
Innovation Solution
Implementing a virtualized peer-to-peer proxy service using virtualization technology to create isolated virtual machines that enforce network routing restrictions and provide consistent content restrictions, allowing IT departments to manage access policies across all devices, including those outside the corporate network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote employees connect directly to the Internet without routing through the corporate intranet, then their ease of operation and access speed improve, but the corporation loses control over content access policies and network security
Solution Approach 1:
The patent introduces a virtual proxy server as an intermediary component that runs within the user's local virtual machine environment. This virtual proxy server acts as a mediator between the user's device and the Internet, enabling direct local access while maintaining corporate policy enforcement through virtualized network routing control.
2Reliability
If corporate IT departments require users to log in to the corporate network to enforce proxy server restrictions, then policy enforcement improves, but user convenience deteriorates due to the cumbersome login requirement
Solution Approach 1:
The system enables self-service policy enforcement by embedding the virtual proxy server directly in the user's local environment. The virtual proxy automatically applies corporate content policies without requiring user authentication or manual login to the corporate network, making the enforcement transparent and convenient for users.
3Speed
If users attach to external networks without going through the corporate intranet, then their access speed improves, but the corporation's ability to monitor and enforce restrictions deteriorates
Solution Approach 1:
The patent shifts the enforcement dimension from network-level routing control to local virtual machine-level control. By deploying the virtual proxy server within the user's local virtualized environment, the system maintains monitoring and policy enforcement capabilities at the application layer even when network routing occurs externally, adding a new dimension of control that is independent of network path.
Data Source
AI summary
A method, apparatus and system for virtualized proxy services are disclosed herein. Specifically, on one embodiment, a virtual proxy may be implemented in a virtual machine host. The virtual proxy may reside within a dedicated or shared virtual partition and may include a set of access restrictions. In one embodiment, a network including virtual machine hosts having virtual proxies may also provide additional peer-to-peer services. More specifically, a virtual proxy on a virtual host may be configured to broadcast/multicast content requests to other virtual hosts on the network prior to accessing the content from a remote location. If the content has previously been downloaded by another virtual host on the network, the virtual proxy on the requesting host may copy the content from the peer virtual host, instead of downloading the content from the remote location again. A variety of security measures may be implemented in one embodiment to ensure data integrity.


