Centralized Firewall Segmentation for SaaS Data Lake Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Creating a production-ready, fully secure data lake in a cloud computing environment is time-consuming and requires significant effort, even with automated SaaS orchestration, as existing technologies struggle to ensure high availability and security across cloud environments.

Innovation Solution

A scalable security approach is implemented using a PaaS stack with embedded cloud-native data processing engines, providing a logically-isolated virtual network and centralized firewalls for secure access, enabling secure encrypted traffic and independent security policy rules for each customer, while maintaining data lake isolation and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated SaaS orchestration is used to provision data lakes, then deployment time is reduced, but security and high availability cannot be ensured across cloud environments

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity and high availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a service provider-managed intermediary layer that sits between the automated SaaS orchestration and the customer's data lake infrastructure. This intermediary provisioned centralized firewalls, virtual private clouds, and security services that automatically enforce security policies and ensure high availability across cloud environments, thereby maintaining fast automated deployment while adding the necessary security and reliability guarantees

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data lake infrastructure into customer-managed components and service provider-managed security components. The service provider provisions separate virtual private clouds and firewall services that are logically isolated but work together to ensure security and availability, allowing automated orchestration to proceed rapidly while security functions are handled by the specialized intermediary infrastructure

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual provisioning is used to ensure security, then security and high availability are achieved, but deployment time increases to 6-9 months

Engineering Contradiction:
Improvesecurity and high availabilityVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The service provider performs preliminary provisioning of security infrastructure including virtual private clouds, firewalls, and security services before customer data is deployed. This pre-established secure infrastructure allows customer data lakes to be rapidly provisioned using automated orchestration without compromising security, reducing deployment time from 6-9 months to a fraction of that time while maintaining security standards

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized firewalls are implemented for multiple customers, then security management is simplified, but system complexity increases

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements universal firewall services and security policies that can be applied across multiple customer environments through the service provider's platform. The centralized firewall infrastructure provides multi-functional capabilities including network segmentation, threat protection, and compliance enforcement that work consistently across different customers and cloud environments, simplifying security management despite the underlying system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12041031B2Scalable security for SaaS data lakes
Publication Date: 2024.07.16 CAZENA INC
  • US12041031B2 patent drawing
  • US12041031B2 patent drawing
  • US12041031B2 patent drawing

AI summary

A method and scalable security service is implemented by a service provider in association with a set of cloud computing services. The method begins by the service provider provisioning a plurality of data lakes across one or more cloud computing services. A data lake is provisioned within a private data cloud of the one or more cloud computing services. To provide scalable security, the service provider configures a virtual firewall in each of two or more regions of the one or more cloud computing services. In particular, the firewall in a given region is associated with a subset of the plurality of data lakes, and wherein the subset comprises at least first and second data lakes associated to at least first and second distinct external enterprise networks. Using the virtual firewall, the service provider then enforces security requirements associated with the subset of the plurality of data lakes via the virtual firewall.