Cloud Security Service Customization via Tenant Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing data centers provide a unified security service that fails to meet the diverse security requirements of different tenants, as the same security measures are applied to all tenants and resources, leading to inefficient resource utilization and inadequate security configurations.

Innovation Solution

A method and device that allow tenants to customize their security services by selecting from a list of available security service types based on their specific needs, with the cloud computing data center determining and executing the chosen security services for virtual machines, enabling tailored security solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a unified security service is provided to all tenants, then security service management is simplified, but the security requirements of different tenants cannot be met

Engineering Contradiction:
Improvesecurity service adaptabilityVSAvoidsecurity service configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security service is segmented into multiple service types (e.g., security group, firewall, intrusion detection) that can be independently selected and configured. Each tenant can choose the specific security services needed for their resources, allowing differentiated security protection while maintaining manageable configuration through standardized service templates.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If different security service measures are applied to meet diverse tenant requirements, then tenant security needs are satisfied, but security resource utilization efficiency decreases

Engineering Contradiction:
Improvesecurity service customizationVSAvoidsecurity resource utilization efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The security service platform provides universal security service templates that can be applied to different resource types (virtual machines, storage, networks). Multiple tenants can share the same security service framework while customizing specific parameters, enabling both customization and efficient resource utilization through standardized multi-functional security components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security services are customized for each tenant, then security requirements are met, but the complexity of security service provision increases

Engineering Contradiction:
Improvesecurity requirement fulfillmentVSAvoidsecurity service provision complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables tenants to self-select and self-configure security services through automated service catalogs. Tenants can independently choose security service types and parameters without manual configuration assistance, reducing the operational complexity for service providers while ensuring reliable security requirement fulfillment through automated service deployment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3062479B1Security service customizing method and apparatus
Publication Date: 2020.12.30 ZTE CORP
  • EP3062479B1 patent drawingFigure 1~2
  • EP3062479B1 patent drawingFigure 3~4
  • EP3062479B1 patent drawingFigure 5~6

AI summary

The disclosure provides a method for customizing a security service and device, relates to the field of information security and solves the problem of incapability of an undiversified security service provision manner in meeting requirements of different tenants. The method includes that: a cloud computing data centre acquires at least one security service type selected by a tenant; and the cloud computing data centre executes corresponding security service according to the at least one security service type selected by the tenant. The technical solutions provided by the disclosure are applicable to a cloud computing system, and enables the cloud computing data centre to provide security service according to a requirement of the tenant.