METHODS AND SYSTEMS OF A MACHINE ACCESS FIREWALL
In one aspect, a computerized method for implementing a machine-identity firewall includes the step of providing a bi-directional Remote procedure call (RPC)-style channels within a uni-directional Hypertext Transfer Protocol Secure (HTTPS) tunnel. The method includes the step of implementing a proxy authentication and a stream-binder on behalf of an entity which cannot embed a native-tunnel endpoint, wherein a proxy end point of the proxy authentication converts a first authentication format to another authentication format and bridges a communication path to another communication path. The method includes the step of implementing a for security key management. The method includes the step of implementing a stream firewall, wherein the stream firewall provides access control on a segmented per-stream basis.
1 . A computerized method for implementing a machine-identity firewall comprising:
providing a bi-directional Remote procedure call (RPC)-style channels within a uni-directional Hypertext Transfer Protocol Secure (HTTPS) tunnel;
implementing a proxy authentication and a stream-binder on behalf of an entity which cannot embed a native-tunnel endpoint, wherein a proxy end point of the proxy authentication converts a first authentication format to another authentication format and bridges a communication path to another communication path;
implementing a for security key management; and
implementing a stream firewall, wherein the stream firewall provides access control on a segmented per-stream basis.
2 . The computerized method of claim 1 , wherein the bi-directional RPC-style channels within the uni-directional HTTPS tunnel is used for a local connectivity.
3 . The computerized method of claim 1 , wherein the bi-directional RPC-style channels within the uni-directional HTTPS tunnel is used for a remote connectivity.
4 . The computerized method of claim 1 , wherein the tunnel end points are at each application and machine which is connected in a peer-to-peer format.
5 . The computerized method of claim 4 , wherein a peer-to-peer communication channel of the peer-to-peer format is used in a segmented implementation of the machine identity firewall or a scalable implementation of the machine identity firewall.
6 . The computerized method of claim 1 , wherein the segmented per-stream basis comprises a human access stream.
7 . The computerized method of claim 1 , wherein the segmented per-stream basis an application stream for each end device.
8 . A computerized system useful for implementing a machine-identity firewall processing comprising:
a processor;
a memory containing instructions when executed on the processor, causes the processor to perform operations that:
provide a bi-directional Remote procedure call (RPC)-style channels within a uni-directional Hypertext Transfer Protocol Secure (HTTPS) tunnel;
implement a proxy authentication and a stream-binder on behalf of an entity which cannot embed a native-tunnel endpoint, wherein a proxy end point of the proxy authentication converts a first authentication format to another authentication format and bridges a communication path to another communication path;
implement a for security key management; and
implement a stream firewall, wherein the stream firewall provides access control on a segmented per-stream basis.
9 . The computerized system of claim 8 , wherein the bi-directional RPC-style channels within the uni-directional HTTPS tunnel is used for a local connectivity.
10 . The computerized system of claim 8 , wherein the bi-directional RPC-style channels within the uni-directional HTTPS tunnel is used for a remote connectivity.
11 . The computerized system of claim 8 , wherein the tunnel end points are at each application and machine which is connected in a peer-to-peer format.
12 . The computerized system of claim 11 , wherein a peer-to-peer communication channel of the peer-to-peer format is used in a segmented implementation of the machine identity firewall or a scalable implementation of the machine identity firewall.
13 . The computerized system of claim 8 , wherein the segmented per-stream basis comprises a human access stream.
14 . The computerized system of claim 8 , wherein the segmented per-stream basis an application stream for each end device.