Cloud Root Service for Uniform Multi-Fabric Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in scaling security operations effectively and maintaining consistent security configurations across multiple cooperative security fabrics, leading to potential security holes and increased complexity.

Innovation Solution

Implementing a cloud-based root service device to manage and configure network security devices within a cooperative security fabric, using a hierarchical structure with a root node to enforce uniform security policies and distribute rules across interconnected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a network security device is specified to perform both network security operations and cooperative security fabric operations, then the device can function as part of the security fabric, but hardware feature selection becomes difficult due to different scaling requirements of the two operations

Engineering Contradiction:
Improvedevice functionalityVSAvoidhardware feature selection
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system separates cooperative security fabric operations from network security operations by introducing a dedicated root service device. The root service device handles fabric management functions (policy distribution, configuration, coordination) while network security devices focus solely on security operations. This segmentation allows each device to be optimized for its specific function without the hardware complexity of supporting both types of operations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If network security systems are expanded to cover more areas, then security coverage is improved, but the complexity of the network increases and unintended security holes may be created

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The root service device acts as an intermediary between multiple cooperative security fabrics and the cloud infrastructure. It centralizes policy distribution, configuration management, and coordination functions, thereby reducing network complexity while maintaining comprehensive security coverage. The intermediary manages the complexity internally while presenting a simplified interface to individual security devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If a cooperative security fabric is managed independently without considering other fabrics, then local security policies can be optimized, but security problems migrating from other fabrics cannot be mitigated

Engineering Contradiction:
Improvepolicy managementVSAvoidsecurity problem mitigation
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The root service device provides universal functionality by managing multiple cooperative security fabrics through a single centralized platform. It can distribute policies across different fabrics, coordinate security responses, and mitigate security problems that migrate between fabrics. This multi-functional approach maintains local policy optimization while adding cross-fabric security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12476937B2Systems and methods for cloud based root service application across multiple cooperative security fabrics
Publication Date: 2025.11.18 FORTINET INC
  • US12476937B2 patent drawing
  • US12476937B2 patent drawing
  • US12476937B2 patent drawing

AI summary

Systems, devices, and methods are discussed for treating a number of network security devices in a cooperative security fabric using a cloud based root.