Distributed Cloud Security Pool for Dynamic Resource Scheduling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for cloud computing in distributed architectures face challenges in achieving unified scheduling and flexible resource expansion, leading to low resource utilization, high operation and maintenance costs, and difficulty in meeting fine-grained security requirements due to traditional centralized security architectures that cannot dynamically expand or contract capacity.

Innovation Solution

A cloud security source pool system based on distributed architecture, where each security device is built as a virtual security machine, forming a cloud resource pool, and multiple request categories are constructed based on historical parameters, with corresponding security sub-models to dynamically adjust resource proportions and correct resource call parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized security architecture is used, then security protection capability is provided, but resource utilization is low and operation and maintenance costs are high

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the centralized security architecture into multiple distributed security service instances deployed across different cloud nodes. Each security service is independent and can be deployed where needed, enabling fine-grained resource allocation and improving utilization while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-point centralized security architecture to a multi-dimensional distributed architecture spanning multiple cloud nodes and layers. This dimensional expansion allows security services to be deployed flexibly across the cloud infrastructure, improving resource utilization without compromising security capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If traditional centralized security architecture is used, then security protection is provided, but capacity cannot be dynamically expanded or contracted

Engineering Contradiction:
Improvesecurity protectionVSAvoiddynamic capacity expansion
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic capacity adjustment by allowing security service instances to be automatically scaled up or down based on real-time traffic patterns and security threats. The system can provision additional security instances during peak periods and release them during low-activity periods, maintaining security coverage while optimizing resource usage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs feedback mechanisms where security metrics and traffic patterns are continuously monitored and fed back to the orchestration system. This feedback loop enables automatic adjustment of security service capacity to match actual demand, providing dynamic adaptability while maintaining robust security protection.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional security devices are deployed as independent hardware or virtual devices, then security functions are provided, but unified scheduling and flexible expansion are difficult

Engineering Contradiction:
Improvesecurity functionsVSAvoidunified scheduling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security service platform where multiple security functions (firewall, intrusion detection, DDoS protection, etc.) are consolidated into a unified virtualized infrastructure. This universal platform can schedule and manage diverse security services through a common control mechanism, simplifying operations while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges previously separate security devices and functions into a unified virtualized security platform. By combining multiple security functions into a single managed ecosystem, the system achieves centralized scheduling control while maintaining the flexibility to deploy individual security services where needed.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If traditional security architecture is used, then basic security protection is provided, but fine-grained security requirements of distributed architectures cannot be met

Engineering Contradiction:
Improvebasic security protectionVSAvoidfine-grained security requirements
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent implements local quality by deploying security services at specific locations within the distributed architecture where they are most needed. Each security service can be precisely positioned and configured to meet the specific security requirements of particular workloads or network segments, providing fine-grained control over security protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250355996A1Cloud security source pool system based on distributed architecture
Publication Date: 2025.11.20 HUANENG INFORMATION TECH CO LTD
  • US20250355996A1 patent drawing

AI summary

The disclosure relates to the technical field of cloud resource pools, and in particular to a cloud security source pool system based on distributed architecture. The system includes: a central control unit, configured for building a cloud resource pool according to security device parameters, where the cloud resource pool includes multiple virtual security machines; and a security monitoring unit, configured for setting multiple request categories according to network structure parameters. The security monitoring unit is further configured for constructing a security sub-model of each of the request categories. Based on the distributed architecture and virtualization technology, each security device is built as a virtual security machine, and a cloud resource pool is built according to all virtual security machines, so as to realize the dynamic call of all security resources, and at the same time, multiple request categories are built based on historical parameters.