FQSG Encapsulation for Cross-Domain Security Context Preservation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security group processing loses context when data packets traverse between functional domains, resulting in inadequate security enforcement at the destination domain, which only applies IP-level 'allow' listings, leading to potential security breaches.
Innovation Solution
Implementing a fully qualified security group (FQSG) that encodes a unique identifier in the data packet header, allowing the destination domain to analyze and enforce security policies based on the source FQSG information using an overlay tunnel, thereby maintaining granular security enforcement across functional domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security group processing is used within a single functional domain, then security enforcement is simple and sufficient, but security context is lost when data packets traverse between functional domains
Solution Approach 1:
The patent extends security group identification from a single-domain dimension to a multi-domain dimension by introducing fully qualified security group (FQSG) identifiers that encode functional instance, functional domain, and security group information. This dimensional expansion allows security context to be preserved and enforced across multiple functional domains while maintaining the simplicity of security group processing within each domain.
2Ease of operation
If IP-level 'allow' listings are applied at the destination domain, then network connectivity is maintained, but granular security enforcement is lost
Solution Approach 1:
The patent applies local quality by maintaining IP-level connectivity rules at the network layer while simultaneously applying granular security group policies at the application layer. The FQSG identifier enables destination domains to enforce security policies with fine-grained control over specific services and applications, rather than applying blanket IP-level allow listings, thus achieving both ease of operation and reliable security enforcement.
3Adaptability or versatility
If security policies are decoupled from substrate technology and IP addresses, then adaptability across different network architectures is improved, but complexity of policy management increases
Solution Approach 1:
The patent introduces FQSG identifiers as an intermediary layer between security policies and network infrastructure. These identifiers encode all necessary contextual information (functional instance, functional domain, security group) in a standardized format that can be transmitted across different network architectures without being tied to specific substrate technologies or IP addressing schemes, thereby achieving policy portability while managing complexity through standardization.
Data Source
AI summary
Methods, systems, and storage media are described for providing network security across multiple functional domains. In particular, some implementations are directed to encapsulating data packets sent from one functional domain to another with fully qualified security group (FQSG) information to allow the destination domain to process the data packet based on the FQSG information from the source domain. Other implementations may be disclosed or claimed.


