Web-Proxy Tunnel Gateway for Firewall Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inter-domain communication across firewalls is complex due to the need for multiple tunnels, which can compromise firewall integrity and expose protected domains to external threats, especially when managing many applications or domains.

Innovation Solution

Implementing a web-proxy system in the second domain that acts as a tunnel gateway, reducing the number of tunnels required by establishing a single tunnel from the first domain through the firewall to the web-proxy system, which then routes signals to multiple applications, thereby minimizing the number of holes needed in the firewall.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple tunnels are established to access multiple applications through a firewall, then inter-domain communication capability is improved, but device complexity and security risk increase

Engineering Contradiction:
Improveinter-domain communication capabilityVSAvoidtunnel management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway server as an intermediary component that mediates between multiple client systems and the firewall. This gateway server consolidates multiple tunnel connections into a single connection point, allowing multiple applications to communicate through the firewall without requiring separate tunnels for each application. The gateway server acts as a central hub that manages and routes communications, thereby reducing the overall complexity of tunnel management while maintaining versatile inter-domain communication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If multiple holes are poked in the firewall to enable application communication, then communication accessibility is improved, but security and firewall integrity deteriorate

Engineering Contradiction:
Improvecommunication accessibilityVSAvoidfirewall integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple communication channels into a single consolidated tunnel connection. Instead of creating separate holes in the firewall for each application, the system combines all application communications through one unified tunnel established to the gateway server. This approach maintains ease of operation by allowing multiple applications to communicate effectively while preserving firewall integrity by minimizing the number of exposed holes in the firewall perimeter.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If a tunnel gateway is implemented to route signals through a single tunnel, then the number of firewall holes is reduced, but signal routing complexity increases

Engineering Contradiction:
Improvefirewall integrityVSAvoidsignal routing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway server is designed with multi-functionality to handle various signal routing requirements through a single tunnel connection. It can identify, route, and manage communications for multiple different applications and client systems simultaneously. This universal design reduces the need for complex specialized routing configurations for each individual application, as the gateway server provides centralized intelligence for managing all communications through the single tunnel, thereby maintaining firewall integrity without proportionally increasing routing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8782773B2Framework for communicating across a firewall
Publication Date: 2014.07.15 AVAYA INC
  • US8782773B2 patent drawing
  • US8782773B2 patent drawing
  • US8782773B2 patent drawing

AI summary

A system for enabling communication between a first domain and a second domain is disclosed. At least the first domain is protected by a firewall. A first data-processing system is provided in the first domain and a second data-processing system provided in second domain. The second domain hosts an application that the first domain desires to access. To enable the communication between the two domains a tunnel is established through the firewall. The tunnel runs from the first data-processing system to the second data-processing system. The second data-processing system provides a web-proxy interface to interface to the application and also acts as a tunnel gateway.