Distributed Security Modules Eliminate Network Chokepoints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions create chokepoints that make networks vulnerable to attacks due to the concentration of security appliances, leading to inefficiencies and over-protection of resources.

Innovation Solution

Decomposing virtual security appliances into security modules and assigning them to different network nodes based on a selected workflow pattern and cost model, optimizing resource usage and distribution across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security appliances are deployed at additional locations throughout the network to alleviate chokepoints, then network vulnerability to attack or disruption is reduced, but computing resources are substantially sacrificed

Engineering Contradiction:
Improvenetwork vulnerabilityVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the monolithic security software solution into multiple security functions that can be distributed across different network nodes. Each security function is implemented as a separate module that can be independently deployed and executed on different virtual machines, eliminating the need for multiple full instances of the complete security solution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security framework where a single security software solution can serve multiple locations simultaneously by distributing its functions across the network. The security appliance at one location provides security services to multiple other locations through networked security functions, eliminating the need for separate deployments at each site.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If additional security appliances are deployed to reduce chokepoints, then network security is improved, but each security appliance becomes over-protected and under-utilized

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity appliance utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security software into modular functions that can be dynamically assigned and load-balanced across multiple physical appliances. This allows traffic to be distributed evenly among available security functions, ensuring high utilization of each appliance while maintaining redundant security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic load balancing and failover mechanisms that automatically adjust traffic distribution based on the current state and utilization of security appliances. When one appliance becomes overloaded or fails, traffic is dynamically rerouted to other appliances with available capacity, optimizing resource utilization in real-time.

Inventive Principle:
Principle #15Dynamics

3Reliability

If a monolithic security software solution is deployed, then comprehensive security coverage is achieved, but chokepoints are created that make the network vulnerable

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monolithic security solution into modular security functions that can be distributed across multiple network nodes. Each node runs only the security functions it needs, eliminating single points of failure while maintaining comprehensive security coverage through the distributed architecture.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If security appliances are concentrated at specific locations, then security enforcement is simplified, but network efficiency is reduced due to traffic steering requirements

Engineering Contradiction:
Improvesecurity enforcementVSAvoidnetwork efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent creates a universal security framework where security functions are distributed throughout the network rather than concentrated at specific locations. Each network node can independently execute security functions, eliminating the need for centralized traffic steering while maintaining consistent security enforcement across the entire network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3259894B1Multi-stage defense-aware security modules placement in the cloud
Publication Date: 2020.06.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3259894B1 patent drawingFigure 1
  • EP3259894B1 patent drawingFigure 2
  • EP3259894B1 patent drawingFigure 3

AI summary

Providing security for one or more network flows may include a security deployment node decomposing one or more virtual security appliances (265) of a logical security architecture (255) into security modules (310). The security deployment node orders the security modules (310) into a sequence (320) that implements a selected workflow pattern (400). The selected workflow pattern (400) may be selected from a workflow pattern database, and may define the security to be provided for a flow, for example, according to known best practices. The sequence (320) is then divided into segments (330), and the segments (330) are assigned to different groups (220) of network nodes (230) in a network (200). For each segment (330), an assignment of each security module (310) in the segment (330) to a network node (230) within the group (220) to which the segment (330) is assigned is computed. The network (200) is then configured according to the assignments.