Host Security Model for Unified Multi-Pool Security Coverage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for multiple resource pools under a tenant require separate security services for each pool, leading to repetitive ordering and lack of appropriate global security services.

Innovation Solution

A method and device that create a host security model under normalized statements, integrating host information to provide unified security services across all resource pools, allowing tenants to order services once for global coverage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security services are provided for each resource pool, then security coverage is achieved for individual pools, but operational complexity increases and repetitive ordering occurs

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate security services into a single unified security service that covers all resource pools under a tenant. The security service platform aggregates security management capabilities and provides comprehensive protection across cloud resources, eliminating the need for separate security services for each resource pool while maintaining complete security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security service platform is designed with universal functionality to manage security across diverse resource pools and cloud environments. It provides multi-functional security capabilities including vulnerability management, threat detection, and incident response that can be applied uniformly across all resource pools, reducing operational complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate security services are ordered for each resource pool, then specific security needs are met, but time and costs increase due to repetitive ordering

Engineering Contradiction:
Improvesecurity service appropriatenessVSAvoidordering time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple security service orders into a single unified ordering process. Tenants can order security services once for all their resource pools rather than placing separate orders for each pool, significantly reducing ordering time and administrative overhead while ensuring consistent security service deployment across all resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary configuration and binding of resource pools to security services in advance. When a tenant orders a security service, the system automatically binds it to all relevant resource pools beforehand, eliminating the need for repeated ordering and configuration processes for each individual pool.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If centralized security service is implemented, then operational efficiency improves, but system complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a security service platform as an intermediary layer between tenants and resource pools. This platform abstracts and simplifies security management operations, providing centralized control and automation while hiding the underlying system complexity. The platform handles resource pool binding, service deployment, and management tasks automatically, improving operational efficiency without exposing users to system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250254200A1Method and apparatus for providing security service, and electronic device and computer storage medium
Publication Date: 2025.08.07 CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
  • US20250254200A1 patent drawing
  • US20250254200A1 patent drawing
  • US20250254200A1 patent drawing

AI summary

A method and apparatus for providing a security service, and an electronic device and a computer storage medium. The method comprises: creating a host security model under the constraint of a normalized sentence (S101); acquiring host information of a tenant, wherein the host information at least comprises: subscription information of a host and asset information of the host (S102); inputting the host information into the security model, so as to obtain security service information, which is output by the security model (S103); and on the basis of the security service information, providing a corresponding security service for the host of the tenant (S104). The security model is created by means of the constraint of the normalized sentence, and by using the security service information, which is output by the security model, corresponding global security services are provided for all hosts of the tenant so as to perform corresponding security prevention and reinforcement.