Fluid Security Layer Rule Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems for cloud-based data centers lack technological innovation, particularly in efficiently managing and migrating security rules across different locations to optimize security, performance, and cost, while maintaining network scalability and bandwidth.

Innovation Solution

A security management capability that uses a processor to select and migrate security rules based on policies associated with cost and processing resources, allowing for intelligent placement and fluid security layer optimization across data centers and communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security rules are statically deployed at fixed locations, then security management is simple, but security performance and cost optimization are limited

Engineering Contradiction:
Improvesecurity rule placement flexibilityVSAvoidsecurity management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security rule migration by allowing security rules to be moved between different locations (source location and destination location) based on changing conditions. The system continuously evaluates policies and automatically migrates security rules to optimize performance, cost, and resource utilization while maintaining security effectiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security management system performs self-service by automatically evaluating policies, selecting optimal locations, and migrating security rules without requiring manual intervention. The system monitors its own performance and autonomously adjusts security rule placement based on current conditions.

Inventive Principle:
Principle #25Self-service

2Productivity

If security rules are migrated frequently to optimize performance, then security efficiency improves, but system complexity and overhead increase

Engineering Contradiction:
Improvesecurity processing efficiencyVSAvoidmigration management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring policy conditions, performance metrics, and cost factors. Based on this feedback, the system intelligently determines when migration is necessary and executes migrations only when beneficial, avoiding unnecessary complexity while maintaining high security processing efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes key parameters such as policy conditions, cost metrics, and performance thresholds to determine optimal migration timing. By dynamically adjusting these parameters based on current system state, the system optimizes security efficiency without excessive migration activity.

Inventive Principle:
Principle #35Parameter changes

3Speed

If security rules are placed closer to data sources to reduce latency, then processing speed improves, but network cost increases

Engineering Contradiction:
Improvesecurity processing speedVSAvoidnetwork transport cost
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

The system dynamically changes the placement location parameter of security rules based on a cost function that balances processing speed and network transport cost. By adjusting this parameter according to current conditions, the system optimizes the trade-off between latency reduction and network cost.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies local quality by placing security rules at different locations depending on specific conditions and requirements. Rather than a uniform placement strategy, the system tailors security rule location to local needs, balancing speed and cost on a per-rule basis.

Inventive Principle:
Principle #3Local quality

4Reliability

If more processing resources are allocated to security rule application, then security enforcement accuracy improves, but overall system performance decreases

Engineering Contradiction:
Improvesecurity enforcement reliabilityVSAvoidoverall system throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically allocates processing resources for security rule application based on current workload and priority conditions. By adjusting resource allocation dynamically, the system maintains high security enforcement reliability while preserving overall system throughput through adaptive resource management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2847964B1Apparatus and method for providing a fluid security layer
Publication Date: 2019.07.10 ALCATEL LUCENT SA
  • EP2847964B1 patent drawingFigure 1
  • EP2847964B1 patent drawingFigure 2
  • EP2847964B1 patent drawingFigure 3

AI summary

A security management capability is presented. The security management capability enables migration of individual security rules between storage/application locations. The migration of a security rule may include selection of a location at which the security rule is to be applied and migration of the security rule to the selected location at which the security rule is to be applied. The selection of the location at which the security rule is to be applied may be performed based on security rule policies and/or security rule location selection information. The security rule is migrated from a current location (e.g., a location at which the security rule is currently applied, a management system, or the like) to the selected location at which the security rule is to be applied. In this manner, a fluid security layer may be provided. The fluid security layer may be optimized for one or more of security level, performance, cost, or the like.