Centralized Firewall Segmentation for SaaS Data Lake Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Creating a production-ready, fully secure data lake in a cloud computing environment is time-consuming and requires significant effort, even with automated SaaS orchestration, as existing technologies struggle to ensure high availability and security across cloud environments.
Innovation Solution
A scalable security approach is implemented using a PaaS stack with embedded cloud-native data processing engines, providing a logically-isolated virtual network and centralized firewalls for secure access, enabling secure encrypted traffic and independent security policy rules for each customer, while maintaining data lake isolation and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated SaaS orchestration is used to provision data lakes, then deployment time is reduced, but security and high availability cannot be ensured across cloud environments
Solution Approach 1:
The patent introduces a service provider-managed intermediary layer that sits between the automated SaaS orchestration and the customer's data lake infrastructure. This intermediary provisioned centralized firewalls, virtual private clouds, and security services that automatically enforce security policies and ensure high availability across cloud environments, thereby maintaining fast automated deployment while adding the necessary security and reliability guarantees
Solution Approach 2:
The patent segments the data lake infrastructure into customer-managed components and service provider-managed security components. The service provider provisions separate virtual private clouds and firewall services that are logically isolated but work together to ensure security and availability, allowing automated orchestration to proceed rapidly while security functions are handled by the specialized intermediary infrastructure
2Reliability
If manual provisioning is used to ensure security, then security and high availability are achieved, but deployment time increases to 6-9 months
Solution Approach 1:
The service provider performs preliminary provisioning of security infrastructure including virtual private clouds, firewalls, and security services before customer data is deployed. This pre-established secure infrastructure allows customer data lakes to be rapidly provisioned using automated orchestration without compromising security, reducing deployment time from 6-9 months to a fraction of that time while maintaining security standards
3Ease of operation
If centralized firewalls are implemented for multiple customers, then security management is simplified, but system complexity increases
Solution Approach 1:
The patent implements universal firewall services and security policies that can be applied across multiple customer environments through the service provider's platform. The centralized firewall infrastructure provides multi-functional capabilities including network segmentation, threat protection, and compliance enforcement that work consistently across different customers and cloud environments, simplifying security management despite the underlying system complexity
Data Source
AI summary
A method and scalable security service is implemented by a service provider in association with a set of cloud computing services. The method begins by the service provider provisioning a plurality of data lakes across one or more cloud computing services. A data lake is provisioned within a private data cloud of the one or more cloud computing services. To provide scalable security, the service provider configures a virtual firewall in each of two or more regions of the one or more cloud computing services. In particular, the firewall in a given region is associated with a subset of the plurality of data lakes, and wherein the subset comprises at least first and second data lakes associated to at least first and second distinct external enterprise networks. Using the virtual firewall, the service provider then enforces security requirements associated with the subset of the plurality of data lakes via the virtual firewall.


