Cloud Software Update Quarantine Between Firewalls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment of software updates in a cloud network is hindered by the need to manually assess and approve updates from external users, leading to inefficiencies and backlogs, especially when dealing with harmful updates, which complicates the installation of beneficial updates.
Innovation Solution
A quarantine system within a virtual local area network in the cloud network allows external updates to be stored in a quarantine zone for review by authorized agents, ensuring efficient deployment of approved updates while preventing harmful ones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual risk assessment by qualified agents is implemented to prevent harmful software updates, then security reliability is improved, but deployment time and operational complexity increase significantly
Solution Approach 1:
The patent segments the software update deployment process into distinct phases: external users submit updates to a quarantine system, qualified agents assess only the quarantined updates, and approved updates are then distributed to computing resources. This segmentation isolates the time-consuming manual assessment to only necessary updates while enabling automated distribution of approved updates, resolving the contradiction between security reliability and deployment time.
Solution Approach 2:
The quarantine system acts as an intermediary between external users and the internal cloud network. It receives, stores, and manages software updates from external sources, presenting them to qualified agents for assessment. This intermediary layer streamlines the workflow by consolidating update collection and management, reducing the time agents spend on administrative tasks while maintaining security oversight.
2Reliability
If manual risk assessment by qualified agents is implemented to prevent harmful software updates, then security reliability is improved, but process complexity increases
Solution Approach 1:
The quarantine system provides self-service functionality by automatically receiving, storing, and managing software updates from external users. It handles update registration, quarantine storage, and status tracking without requiring manual intervention for each update submission. This automation of routine tasks reduces process complexity while maintaining security through mandatory agent assessment of quarantined updates.
3Productivity
If external users are allowed to deploy software updates directly to computing resources, then productivity is improved, but security risk increases
Solution Approach 1:
The system performs preliminary action by requiring external users to submit software updates to the quarantine system before they can be deployed to computing resources. Updates are quarantined and assessed by qualified agents prior to approval. This preliminary security check prevents harmful updates from reaching computing resources while still enabling efficient deployment of approved updates through the automated distribution process.
4Reliability
If qualified agents manually evaluate each software update request, then update security is improved, but administrative burden increases
Solution Approach 1:
The patent extracts the time-consuming administrative tasks from the qualified agents' workflow by implementing an automated quarantine system. The system automatically receives, stores, and tracks software updates from external users, presenting only the essential assessment information to agents. This extraction of routine administrative burdens allows agents to focus on the critical security assessment task, improving update security while easing administrative operations.
Data Source
AI summary
A quarantine system could be disposed between an outer firewall and an inner firewall. The quarantine system may include persistent storage containing mappings between computing devices disposed within the inner firewall and data sources disposed outside the outer firewall. The quarantine system may include one or more processors configured to perform operations that include requesting and receiving, based on the mappings, a software-related update from a data source, the software-related update being targeted for deployment on the computing devices. The operations may also include assigning the software-related update for review by a group of one or more agents authorized to approve or reject the software-related update. The operations may also receiving an indication that the software-related update has been approved by the one or more agents and, responsive to receiving the indication, transmitting, based on the mappings, the software-related update to a recipient device within the inner firewall.


