Centralized Secure Offload for Distributed Security Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures struggle to maintain the continuous availability and security of security enforcement points, particularly in hostile zones, where sensitive data is exposed and critical for managing traffic and security events, while also ensuring the protection of internal and external threats.

Innovation Solution

A centralized secure offloading system for security services, where security enforcement points in less trusted zones communicate with a security server hosting logic in a more trusted zone, allowing for the offloading of security services such as policy, monitoring, digital signature verification, and business resilience services, maintaining critical information in a secure environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security enforcement points are deployed in hostile zones to control traffic and security events, then security coverage and enforcement capability are improved, but the exposure of sensitive data and vulnerability to attacks increase

Engineering Contradiction:
Improvesecurity enforcement capabilityVSAvoidexposure to malicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides security enforcement functionality into two segments: security enforcement points deployed in hostile zones that handle traffic control and event generation, and a centralized security server in a protected zone that hosts sensitive security services and data. This segmentation allows enforcement capability to be distributed while concentrating sensitive functions in a secure location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces an intermediary communication mechanism between security enforcement points and the centralized security server. The enforcement points communicate security events and requests to the server, which processes them and returns decisions. This intermediary architecture allows enforcement points to operate in hostile zones without directly exposing sensitive security services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security services are distributed across multiple enforcement points in hostile zones, then security coverage is improved, but the availability and security of critical information are compromised

Engineering Contradiction:
Improvesecurity coverageVSAvoidavailability of critical information
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The invention extracts critical security services and sensitive data from distributed enforcement points and relocates them to a centralized security server in a protected zone. This extraction maintains broad security coverage through distributed enforcement points while protecting critical information by removing it from hostile environments.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transitions from a single-dimensional distributed model to a multi-dimensional architecture where enforcement points operate in hostile zones while the security server operates in a protected zone. This dimensional separation allows the system to simultaneously achieve broad coverage and protect critical information by operating in different security zones.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If management nodes maintain direct connectivity to all security enforcement points in hostile zones, then real-time monitoring capability is improved, but the security risk and complexity of management increase

Engineering Contradiction:
Improvereal-time monitoring capabilityVSAvoidmanagement connectivity requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The invention merges multiple management connectivity requirements into a single centralized security server. Instead of management nodes needing direct connectivity to numerous distributed enforcement points, all management communication is routed through the centralized server. This reduces management complexity while maintaining real-time monitoring capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized security server acts as an intermediary between management nodes and security enforcement points. Management nodes communicate security policies and receive monitoring data through the server, which forwards commands to and collects data from enforcement points. This intermediary role simplifies management connectivity while preserving real-time monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10348681B2Centralized secure offload of security services for distributed security enforcement points
Publication Date: 2019.07.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10348681B2 patent drawing
  • US10348681B2 patent drawing

AI summary

Embodiments of the present invention provide methods, systems and computer program products for the centralized, secure offloading of security services for distributed security enforcement points. In an embodiment, a network data processing system can be configured for centralized secure offload of security services for distributed security enforcement points and can include a set of security enforcement points controlling communication flows between devices in different less trusted zones of protection. The system also can include a security server communicatively coupled to the security enforcement points and hosting security services logic disposed in a more trusted zone of protection. Each of the security enforcement points can include an interface to the security services logic and program code enabled to offload security related services processing through the interface to the security services logic disposed in the more trusted zone of protection.