Container Orchestration with Service Gateway for Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of virtualized private clouds for infrastructure-as-a-service delivery leads to unsecure virtual machine sprawl, affecting security compliance and regulatory requirements, and traditional datacenters face challenges in configuring network connectivity for secure workload mobility and policy consistency, while virtual networking services can be cost-prohibitive for production deployments.

Innovation Solution

Software for orchestrating application containers automates the provisioning of virtualized applications, providing secure segmentation and rapid deployment by consolidating physical resources on shared infrastructure, using preconfigured virtual networking and security services, and simplifying virtual networking and security through a wizard-based provisioning model, with features like SLA management and automated licensing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machine sprawl is increased to meet infrastructure-as-a-service delivery, then service provisioning capability is improved, but security compliance deteriorates

Engineering Contradiction:
Improveservice provisioning capabilityVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments virtual machines into application containers with isolated network segments, where each container operates within defined security boundaries. This segmentation allows rapid provisioning while maintaining security compliance through enforced isolation between containers and controlled access to network resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a service gateway as an intermediary component that mediates all network traffic between application containers and external networks. This gateway enforces security policies, manages compliance requirements, and enables automated provisioning while maintaining security controls, thus resolving the contradiction between speed and compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional network connectivity configuration is used for secure workload mobility, then security policy consistency is improved, but deployment complexity increases

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal service gateway that handles multiple functions including network address translation, security policy enforcement, load balancing, and container orchestration. This multi-functional approach maintains security policy consistency across diverse workload scenarios while reducing deployment complexity through a single standardized component rather than multiple specialized configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the fundamental parameters of network connectivity by transitioning from traditional IP-based networking to container-based network segmentation with standardized communication protocols. This parameter change enables automated provisioning and consistent security policies while reducing manual configuration complexity, as containers are provisioned with predefined network parameters rather than requiring custom network setup.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If virtual networking services are deployed for production workloads, then network security is improved, but cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidoperating cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple virtual networking functions including firewalls, load balancers, network address translation, and security policy enforcement into a single service gateway component. This consolidation maintains comprehensive network security while reducing operating costs by eliminating the need for multiple separate virtual networking services and reducing resource overhead through shared infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10999406B2Attaching service level agreements to application containers and enabling service assurance
Publication Date: 2021.05.04 CISCO TECHNOLOGY INC
  • US10999406B2 patent drawing
  • US10999406B2 patent drawing
  • US10999406B2 patent drawing

AI summary

Providing a template for orchestration of a cloud provided service in a datacenter. This template can include virtual processing services, virtual networking services, storage services, and service level requirements that a user or administrator can select for the cloud provided service. Based on the template the cloud provided service can be provisioned according to the requirements of the service level agreement.