Dynamic Address Mapping for Cloud Node Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in securing dynamic node infrastructures, as the flexibility in scaling limits the control over security access rules, making it difficult to implement traditional security models like DMZ architectures.

Innovation Solution

A secure distributed computing platform that dynamically reconfigures node addresses through proactive or reactive address-mapping, allowing nodes to change platform addresses in response to events, thereby enhancing security by preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud computing dynamically scales application infrastructure, then flexibility and resource efficiency are improved, but control over security access rules deteriorates

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic address mapping where platform addresses are not statically assigned but dynamically allocated and reconfigured based on current infrastructure state. This allows the security model to adapt to changing node configurations while maintaining controlled access, resolving the contradiction between infrastructure flexibility and security control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary address mapping layer between application nodes and physical infrastructure. This mapping table acts as a mediator that decouples application-level addressing from physical node addresses, allowing security rules to be enforced at the mapping layer while maintaining flexible underlying infrastructure scaling.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional DMZ architecture is implemented with static node addresses, then security partitioning is improved, but adaptability to dynamic cloud infrastructure deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces static DMZ address assignments with dynamic address mapping that can adapt to changing infrastructure. The mapping table can be reconfigured to create virtual DMZ zones dynamically, maintaining security partitioning principles while adapting to cloud infrastructure fluidity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds an abstract addressing dimension between physical nodes and application access. This virtual addressing layer allows security zones to be defined in the mapping space rather than being constrained to physical network segments, enabling DMZ-like security partitions in dynamic cloud environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If node addresses are dynamically reconfigured, then security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service address mapping where the platform automatically manages address allocation and remapping without manual intervention. The system autonomously handles security-related address reconfiguration in response to detected events, reducing operational complexity while maintaining enhanced security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where application analyzers monitor system state and trigger address remapping events based on detected conditions. This closed-loop control automates security responses while keeping the system manageable through event-driven rather than continuously complex address management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8782788B2Systems, methods, and apparatus for improved application security
Publication Date: 2014.07.15 VIASAT INC
  • US8782788B2 patent drawing
  • US8782788B2 patent drawing
  • US8782788B2 patent drawing

AI summary

A secure computing system includes a plurality of application nodes, each node including a device address, a platform address, and a node ID. A mapping is maintained between each of the node IDs and the platform addresses. A mapping is also maintained between each of the platform addresses and the device addresses. An analyzer analyzes communication to application nodes to detect a predetermined event. In response to the detection of an event, a reconfigurator may change a platform address of one or more of the application nodes. The mappings of addresses are updated in response to the change. A consensus state maintainer may ensure that application nodes communicating with each other are provided with the updated mapping. By changing the platform addresses of the application nodes, an ability of an external threat to communicate with the application nodes may be reduced.