Contextual Security Platform for Hybrid Cloud Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security mechanisms struggle to enforce policies across hybrid computer networks that combine traditional hardware resources and virtual resources from private and public cloud infrastructure services, particularly in preventing unauthorized access and ensuring secure communication between workload units.

Innovation Solution

A contextual security platform that automatically configures and enforces network security policies by mapping application-level security rules to network-level security rules across various infrastructure points, including routers, switches, operating systems, and cloud providers, using a software-based system to discover network flows, enforce micro-segmentation, and continuously monitor for threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network security mechanisms operate at the network level with traditional hardware resources, then security policies can be enforced at routers and firewalls, but they cannot effectively enforce policies across virtual resources and workload units in hybrid cloud infrastructures

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidsecurity policy effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments security policy enforcement into multiple levels: network-level enforcement at traditional hardware resources and workload-level enforcement at virtual resources. This is achieved by deploying security mechanisms both at the network infrastructure level and within individual workload units, allowing each segment to enforce appropriate security policies for its specific context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security mechanism that bridges traditional network-level security and cloud workload security. This intermediary layer translates high-level security policies into specific enforcement rules that can be applied across both hardware and virtual resources, enabling unified policy management across hybrid infrastructures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security mechanisms are implemented within the operating system, then they can provide fine-grained control over applications, but they become vulnerable to threats that gain root access and can disable security rules

Engineering Contradiction:
Improvesecurity control granularityVSAvoidsecurity mechanism vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements nested security mechanisms where workload-level security enforcement is embedded within the application layer, which itself runs on the operating system. This nested structure allows security controls to operate at multiple levels of abstraction, with the innermost layer providing fine-grained application control while outer layers provide system-level protection that cannot be easily disabled by root access.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If multiple network security enforcement mechanisms are deployed across hybrid infrastructure, then comprehensive security coverage is achieved, but the complexity of configuring and managing these mechanisms increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity mechanism configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security policy framework that can be applied across diverse hardware and virtual resources. The same high-level security policies can be enforced uniformly across routers, firewalls, and workload units, eliminating the need for separate complex configuration processes for each mechanism type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms that automatically monitor the state of security enforcement across the hybrid infrastructure and dynamically adjust configuration as needed. This feedback loop reduces manual configuration complexity by automatically responding to changes in the network environment and security threats.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If cloud service providers offer built-in security controls, then security can be enforced at the cloud infrastructure level, but these controls cannot provide sufficient isolation from workload-specific security requirements

Engineering Contradiction:
Improvecloud infrastructure securityVSAvoidsecurity domain isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments security enforcement into cloud infrastructure level and workload level, with each layer handling appropriate security concerns. Cloud provider security controls enforce policies at the infrastructure level, while workload-level mechanisms enforce application-specific security requirements, providing both broad coverage and specialized protection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11962622B2Automated enforcement of security policies in cloud and hybrid infrastructure environments
Publication Date: 2024.04.16 MAGENTA SECURITY HOLDINGS LLC
  • US11962622B2 patent drawing
  • US11962622B2 patent drawing
  • US11962622B2 patent drawing

AI summary

To prevent un-authorized accesses to data and resources available in workloads on an organization's or enterprise's computer network, various improvements to automated computer network security processes to enable them to enforce network security policies using native network security mechanisms to control communications to and/or from workload units of applications running on different nodes within hybrid computer network infrastructures having both traditional hardware resources and virtual resources provided by private and public cloud infrastructure services.