Network Security Gateway Cloud Logging Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network solutions for large business enterprises require user registration for accessing cloud-based logging services, which complicates user access and increases security threats due to increased complexity.

Innovation Solution

A network security gateway with integrated graphical user interface and cloud-based logging service access module automatically registers itself with the cloud-based logging service, allowing seamless access and logging without user registration, thereby simplifying user access and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user registration is required for accessing cloud-based logging services, then security control is improved, but user access complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoiduser access complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network security gateway automatically performs registration with the cloud-based logging service without requiring manual user registration. The gateway uses its own credentials to autonomously create accounts and establish connections, eliminating the need for administrators to manually register users while maintaining security through automated authentication mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network security gateway serves multiple functions: it acts as both the network security appliance and the registered user of the cloud-based logging service. By integrating the logging service access directly into the gateway, the system eliminates the need for separate user account management while maintaining secure access control through the gateway's inherent security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual user registration is implemented, then account security is improved, but system complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network security gateway autonomously handles account creation and registration with the cloud-based logging service. The gateway automatically manages its own credentials, authentication, and account maintenance without requiring manual intervention, thereby maintaining account security through automated secure authentication while eliminating the complexity of manual account management systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If separate user registration is required, then access control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoiduser access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network security gateway integrates multiple functions including network security enforcement and cloud-based logging service access. By consolidating these functions into a single entity that automatically manages its own registration, the system maintains secure access control through the gateway's security mechanisms while dramatically simplifying user operation to merely enabling the logging feature without any registration steps.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If automated registration is implemented, then ease of operation is improved, but security requirements increase

Engineering Contradiction:
Improveuser access easeVSAvoidsecurity requirements
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network security gateway performs automated registration using its own embedded credentials and authentication mechanisms. The automation simplifies user operation to a single enablement action, while security is maintained through the gateway's inherent security features including secure credential storage, automated authentication protocols, and encrypted communication with the cloud service.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10116626B2Cloud based logging service
Publication Date: 2018.10.30 FORTINET INC
  • US10116626B2 patent drawing
  • US10116626B2 patent drawing
  • US10116626B2 patent drawing

AI summary

Methods and systems are provided for facilitating access to a cloud-based logging service. According to one embodiment, access to a cloud-based logging service is integrated within a network security appliance by automatically configuring access settings for the logging service and creating an account for the security appliance with the logging service. A log is created within the logging service by making use of the automatically configured access settings and the account. A request is received by the security appliance to access data associated with the log. Responsive thereto and without requiring separate registration of a network administrator with the cloud-based logging service, the data is retrieved by the security appliance from the logging service and is presented via a graphical user interface of the security appliance.