Hierarchical Security Gateway System for Cloud Threat Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computer systems on cloud platforms face challenges in managing distinct security needs and optimizing resource utilization to protect against infiltration and data exfiltration attacks, as existing solutions fail to efficiently apply tailored security measures across diverse computing applications.

Innovation Solution

A system comprising a main controller, local controllers, and security gateway systems that manage security services by determining the launch or termination of local controllers and security gateway systems, collecting and distributing threat intelligence data, and applying security policies to protect computing applications, thereby enhancing security and resource efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distinct security measures are applied to each enterprise computing system, then security protection quality is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protection qualityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security management into multiple hierarchical levels: cloud service providers implement baseline security measures, while enterprise computing systems can optionally apply additional distinct security measures. Local controllers are deployed at individual enterprise systems for customized security, while a central controller coordinates across multiple systems. This segmentation allows security protection quality to be improved at each level without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including local controllers at enterprise systems and a central controller that mediates between cloud service providers and enterprise systems. These intermediaries handle the complexity of coordinating distinct security measures across multiple systems, allowing each enterprise to maintain customized security without directly managing the complexity of inter-system coordination. The intermediaries abstract and manage the security policy distribution and threat intelligence sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tailored security measures are applied to each computing application, then security effectiveness is improved, but computational resources and processing time are consumed

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-distributing security policies and threat intelligence data to local controllers before security threats materialize. The central controller proactively pushes updated security measures to enterprise computing systems based on emerging threats, allowing local controllers to immediately enforce protection without real-time computational overhead. This preliminary distribution of security configurations reduces the computational burden during actual security operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Local controllers at enterprise computing systems autonomously enforce security policies and apply threat intelligence data without requiring continuous centralized processing. Each local controller independently evaluates incoming traffic against distributed security policies and threat intelligence, enabling tailored security measures to be applied at each system without proportionally increasing central computational resources. The system enables self-service security enforcement at the edge.

Inventive Principle:
Principle #25Self-service

3Productivity

If security services are managed centrally for multiple virtual clusters, then resource utilization efficiency is improved, but response time and adaptability to local threats decrease

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidresponse time
Core Design Contradiction:
ProductivityVSSpeed

Solution Approach 1:

The patent implements local quality by deploying intelligent local controllers at each enterprise computing system that can autonomously enforce security policies and respond to threats locally. Each local controller is equipped with distributed threat intelligence data and can immediately respond to security events without waiting for centralized commands. This local autonomy ensures fast response times while the central controller maintains overall resource coordination and policy management for efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system adds a spatial dimension to security management by distributing controllers across multiple hierarchical levels (central controller at cloud level, local controllers at enterprise system level). This dimensional distribution allows the system to simultaneously achieve centralized resource coordination efficiency and localized rapid response capability. The multi-dimensional controller architecture resolves the trade-off by operating in both centralized and decentralized modes concurrently.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11457047B2Managing computer security services for cloud computing platforms
Publication Date: 2022.09.27 CISCO TECHNOLOGY INC
  • US11457047B2 patent drawing
  • US11457047B2 patent drawing
  • US11457047B2 patent drawing

AI summary

A computer-implemented method of managing security services for one or more cloud computing platforms is disclosed. The method comprises receiving, by a security gateway system having a processor, a digital communication related to one of one or more computing applications hosted by a virtual cluster for private use on a cloud computing platform, the security gateway system residing within the cloud computing platform, the security gateway system performing network security gateway functions for the one or more computing applications. The method also comprises storing the digital communication in association with a timestamp in a storage device. The method further comprises receiving a piece of threat intelligence data indicating a security threat from a main controller residing outside the virtual cluster; storing the piece of threat intelligence data in a database; and determining whether the piece of threat intelligence data applies to any of the digital communications in the storage device. Finally, the method comprises transmitting an estimate of an extent or timing of an impact of the security threat based on the determining.