Cloud Security Center for Multi-Tenant Network Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions are costly and do not scale well with increasing user numbers, requiring frequent updates to address new threats and infrastructure needs, which can be inefficient and resource-intensive for organizations.
Innovation Solution
A cloud-based security center system that provides scalable security services through geographically distributed security centers, utilizing routing engines and service aggregators to manage and enforce security policies across multiple customer networks, enabling secure communication paths over public data networks with minimal modifications to existing infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security solutions are deployed for each organization, then security protection is provided, but costs increase and scalability deteriorates as user numbers grow
Solution Approach 1:
The patent combines multiple organizations' security needs into a single shared security infrastructure. The security appliance is physically deployed at one location but serves multiple customer networks through virtualization, allowing multiple tenants to share the same hardware resources while maintaining isolated security policies for each organization.
Solution Approach 2:
The security appliance is designed to provide universal security services to multiple different customer networks simultaneously. A single appliance can serve multiple tenants with different security requirements through virtual machine instances, making the system multi-functional rather than dedicated to a single organization.
2Productivity
If security infrastructure is scaled up to service new users, then network capacity increases, but security costs and complexity increase proportionally
Solution Approach 1:
The patent merges multiple security functions and multiple customer networks into a single shared infrastructure. Instead of deploying separate security appliances for each customer, the system combines them into one physical appliance that handles multiple networks, thereby increasing capacity without proportional increases in complexity.
Solution Approach 2:
The patent uses virtual machine copies to provide security services to multiple tenants. A single security appliance can create virtual copies of security functions for different customers, allowing the system to scale capacity by virtualization rather than by adding physical hardware complexity.
3Reliability
If dedicated security hardware and software are acquired for each network, then security coverage is comprehensive, but resource utilization efficiency decreases
Solution Approach 1:
The patent merges dedicated security resources from multiple organizations into a single shared pool. The security appliance consolidates hardware and software resources that would otherwise be duplicated across multiple separate deployments, improving resource utilization while maintaining comprehensive security coverage through virtualization.
Solution Approach 2:
The security appliance is designed to perform multiple security functions for multiple different networks simultaneously. This multi-functional design ensures comprehensive security coverage across all tenants while maximizing resource utilization by having a single infrastructure serve multiple purposes rather than dedicated resources sitting underutilized.
Data Source
AI summary
An approach is provided for performing cloud based computer network security services. Security policies are established for each of a number of subscribers. The subscribers are provided access to the security services via a common network cloud managed by the service provider. The security services are administered according to a multi-tenancy format, which enables the subscribers' data communications to be separately processed. The security services include network firewalling and filtering of content originating from or destined to one or more networks associated with the subscribers.


