Network Management Service for Restricted Region Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for vetting changes in restricted network regions often cause deployment bottlenecks due to inefficiencies in assessing the impact of changes, potentially introducing unintended security vulnerabilities.
Innovation Solution
A computer-implemented method that includes receiving a deployment bundle request for a restricted network, authenticating change management tickets, and performing security impact analyses to ensure authorized access and deployment, using a Cloud Infrastructure Orchestration Service (CIOS) to manage and authorize changes through a unidirectional gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional techniques are used for vetting changes to restricted regions, then network security is maintained, but deployment efficiency deteriorates due to bottlenecks
Solution Approach 1:
The system performs preliminary security impact analysis and authentication before deployment by requiring change management tickets to be created and approved in advance. The ticket tracking system authenticates tickets and determines authorization status before the deployment bundle is applied to the restricted region, preventing security issues rather than detecting them after deployment.
Solution Approach 2:
The patent introduces a ticket tracking system as an intermediary between the deployment process and the restricted region. This intermediary authenticates change management tickets, tracks authorization status, and coordinates with source control management services to determine if deployment bundles are authorized, thereby streamlining the security vetting process without directly blocking deployment.
2Object-affected harmful factors
If comprehensive security impact analysis is performed for all changes, then security vulnerabilities are reduced, but processing time increases
Solution Approach 1:
The system performs security impact analysis selectively rather than universally. The ticket tracking system determines whether a change management ticket has been authenticated and whether authorization exists before performing full security analysis. Only changes with valid, authenticated tickets undergo comprehensive security impact analysis, while others are quickly rejected without full analysis.
Solution Approach 2:
The security vetting process is segmented into distinct phases: ticket authentication by the ticket tracking system, authorization determination, and then security impact analysis. This segmentation allows the system to quickly filter out unauthorized changes at the authentication stage without investing time in full security analysis for all deployment requests.
3Reliability
If multiple authentication and authorization checks are performed, then deployment security is improved, but system complexity increases
Solution Approach 1:
The ticket tracking system serves multiple functions: it tracks change management tickets, authenticates tickets, determines authorization status, and coordinates with source control management services. This multi-functional approach consolidates what could be separate complex systems into a single unified platform, reducing overall system complexity while maintaining comprehensive security checks.
Solution Approach 2:
The patent merges ticket tracking, authentication, and authorization determination into a single integrated system. The ticket tracking system combines these functions and interfaces with source control management services through standardized protocols, reducing the number of separate components and their interconnections compared to having separate systems for each security function.
Data Source
AI summary
A computing device may receive a request to provide a deployment bundle to a restricted network. The deployment bundle can include information identifying a plurality of changes to be made to the restricted network. The request can include at least one of a change management ticket, a network identifier or a file identifier. The computing device may access a ticket tracking system to authenticate the change management ticket, the change management ticket indicating whether the plurality of changes are authorized. The computing device may access a source control management service to determine, based at least in part on the network identifier or the file identifier, if the deployment bundle is authorized to access the restricted network. The computing device may provide the deployment bundle to a restricted region computing device configured to apply the deployment bundle to the restricted region. Numerous other aspects are described.


