FQSG Encapsulation for Cross-Domain Security Context Preservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security group processing loses context when data packets traverse between functional domains, resulting in inadequate security enforcement at the destination domain, which only applies IP-level 'allow' listings, leading to potential security breaches.

Innovation Solution

Implementing a fully qualified security group (FQSG) that encodes a unique identifier in the data packet header, allowing the destination domain to analyze and enforce security policies based on the source FQSG information using an overlay tunnel, thereby maintaining granular security enforcement across functional domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security group processing is used within a single functional domain, then security enforcement is simple and sufficient, but security context is lost when data packets traverse between functional domains

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsecurity context
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extends security group identification from a single-domain dimension to a multi-domain dimension by introducing fully qualified security group (FQSG) identifiers that encode functional instance, functional domain, and security group information. This dimensional expansion allows security context to be preserved and enforced across multiple functional domains while maintaining the simplicity of security group processing within each domain.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If IP-level 'allow' listings are applied at the destination domain, then network connectivity is maintained, but granular security enforcement is lost

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by maintaining IP-level connectivity rules at the network layer while simultaneously applying granular security group policies at the application layer. The FQSG identifier enables destination domains to enforce security policies with fine-grained control over specific services and applications, rather than applying blanket IP-level allow listings, thus achieving both ease of operation and reliable security enforcement.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If security policies are decoupled from substrate technology and IP addresses, then adaptability across different network architectures is improved, but complexity of policy management increases

Engineering Contradiction:
Improvepolicy portabilityVSAvoidpolicy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces FQSG identifiers as an intermediary layer between security policies and network infrastructure. These identifiers encode all necessary contextual information (functional instance, functional domain, security group) in a standardized format that can be transmitted across different network architectures without being tied to specific substrate technologies or IP addressing schemes, thereby achieving policy portability while managing complexity through standardization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240187453A1Network security for multiple functional domains
Publication Date: 2024.06.06 SALESFORCE INC
  • US20240187453A1 patent drawing
  • US20240187453A1 patent drawing
  • US20240187453A1 patent drawing

AI summary

Methods, systems, and storage media are described for providing network security across multiple functional domains. In particular, some implementations are directed to encapsulating data packets sent from one functional domain to another with fully qualified security group (FQSG) information to allow the destination domain to process the data packet based on the FQSG information from the source domain. Other implementations may be disclosed or claimed.