Decoupled Network Security Software for Distributed Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The perimeter-based security model is inflexible and ineffective in adapting to evolving security threats, particularly with the increased adoption of bring-your-own-device policies, which introduces additional security concerns due to the potential for malicious software and rogue code within legitimate software.

Innovation Solution

Decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment, allowing for on-demand access to security services through open APIs, enabling each asset to be protected according to its specific requirements rather than the collective requirements of all assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter-based security model with dedicated hardware security appliances is used, then security protection is provided for the network, but flexibility and adaptability to evolving security threats deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidflexibility to adapt to evolving threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traditional monolithic security appliance into separate virtual security functions (VNFs) that can be independently deployed, managed, and updated. Each security function (firewall, IDS, IPS, etc.) becomes a separate virtual component that can be dynamically provisioned based on specific threat requirements, enabling flexible adaptation while maintaining comprehensive security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security by allowing security functions to be dynamically created, moved, scaled, and updated in the distributed environment. Security policies and threat signatures can be updated in real-time without hardware changes, and security services can be dynamically allocated to different network segments based on evolving threats and traffic patterns.

Inventive Principle:
Principle #15Dynamics

2Reliability

If perimeter-based security model with dedicated hardware devices is used, then security functions are provided, but rapid deployment and updating capability deteriorates

Engineering Contradiction:
Improvesecurity function provisionVSAvoiddeployment and updating time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses virtualization to create virtual copies of security functions that can be rapidly deployed across the distributed environment. Virtual security appliances can be instantiated from templates and copied to multiple locations simultaneously, enabling rapid deployment of security updates and new security functions without physical hardware installation delays.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements preliminary action by pre-configuring security function templates and threat signature databases that can be quickly instantiated when needed. Security updates and new security functions can be prepared in advance and rapidly deployed across the distributed environment without requiring time-consuming hardware installation and configuration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If collective security requirements for all assets are applied, then perimeter protection is achieved, but specific asset security requirements are not met

Engineering Contradiction:
Improveperimeter protectionVSAvoidspecific asset security protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing each virtual security function to be customized with specific security policies, rules, and parameters tailored to the requirements of individual assets or asset groups. Different security levels and types can be applied to different assets within the same network, enabling precise protection matching each asset's specific needs while maintaining overall perimeter security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11652847B2Decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment
Publication Date: 2023.05.16 KYOCERA CORP
  • US11652847B2 patent drawing
  • US11652847B2 patent drawing
  • US11652847B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment. A computer system includes a processor that can execute computer-executable instructions to perform various operations. The processor can perform operations to provide security services to one or more customer platforms. The operations can include receiving a network security software component from a security service provider, and deploying the network security software component within a distributed computing environment so that the network security software component can be executed by a computing resource of the distributed computing environment to provide a security service to the customer platform(s). The network security software component includes a software component that has been decoupled from a hardware component of a network security device by the security service provider.