Cloud Tenant Network Security With Distributed Firewall Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security management systems in public clouds face challenges in effectively managing and controlling intra-cloud attack threats, leading to vulnerabilities in network security for cloud tenants.

Innovation Solution

Implementing a distributed firewall configuration that utilizes private network-level, subnet-level, and instance-level management and control units to manage network traffic based on access control policies, distributing these policies to instances without redirecting traffic, thereby enhancing security management and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized traffic processing cluster is used to detect and control network traffic, then network security management is simplified, but the system cannot effectively manage intra-cloud attack threats and cloud tenants must redirect traffic

Engineering Contradiction:
Improvesimplicity of security managementVSAvoideffectiveness against intra-cloud threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized security management function into distributed firewall capabilities at multiple levels (private network-level, subnet-level, and instance-level management and control units). Each unit independently enforces access control policies for its scope, eliminating the need for traffic redirection to a central cluster while effectively managing intra-cloud threats through localized security enforcement.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traffic is redirected to an independent traffic processing cluster for security detection, then centralized security control is achieved, but network traffic management becomes complex and time-consuming

Engineering Contradiction:
Improvecentralized security controlVSAvoidtime for traffic management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service security control where each management and control unit (private network-level, subnet-level, instance-level) autonomously detects and enforces access control policies for its own scope. This eliminates the need for time-consuming traffic redirection to external security clusters, as security detection and control are performed in-place by the distributed firewall units themselves.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If access control policies are enforced through centralized traffic detection, then security policy management is simplified, but the system lacks adaptability to different cloud tenant scenarios

Engineering Contradiction:
Improveease of policy managementVSAvoidadaptability to cloud tenant scenarios
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments security management into hierarchical levels (private network-level, subnet-level, instance-level), allowing access control policies to be customized for different scopes and cloud tenant scenarios. Each level can independently manage policies appropriate to its domain, providing both ease of management through modular structure and adaptability through scenario-specific policy enforcement at each level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling each management and control unit to enforce access control policies tailored to its specific scope and requirements. Private network-level units handle broad tenant policies, subnet-level units manage intermediate security requirements, and instance-level units enforce granular application-specific rules, allowing each level to be optimized for its local context while maintaining overall policy consistency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12445454B2Network security management method and computer device
Publication Date: 2025.10.14 TENCENT CLOUD COMPUTING (BEIJING) CO LTD
  • US12445454B2 patent drawing
  • US12445454B2 patent drawing
  • US12445454B2 patent drawing

AI summary

A network security management method is provided. In the method, configuration data that includes at least one access control policy for a network asset of a target cloud tenant is received. The network asset includes a private network, a subnet of the private network, and a cloud instance of the subnet. A network management and control unit and an access control policy set corresponding to the network management and control unit are determined according to the configuration data. The network management and control unit includes one or more of a private network-level management and control unit, a subnet-level management and control unit, and an instance-level management and control unit. The access control policy set of the network management and control unit is transmitted to the cloud instance that is associated with the network management and control unit to manage network traffic of the cloud instance.