Network Security Controller Isolating Sensitive Data Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In dynamic virtualized data centers, it is challenging to securely group servers handling confidential data together while ensuring that sensitive information is not exposed to non-authorized servers, as sensitive data may be stored on compute servers but not on storage or database servers, and data needs to be shared selectively among servers.
Innovation Solution
A computer program product and network system that identifies network processing elements handling sensitive information, analyzes packets for such data, classifies these elements, and moves them into a secure closed user group (CUG) of network processing elements to isolate and protect sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If servers are dynamically virtualized and distributed across the network, then resource utilization and flexibility are improved, but security control and isolation of sensitive data become more difficult
Solution Approach 1:
The patent introduces a security controller as an intermediary component that mediates between the dynamic virtualized servers and security requirements. The controller analyzes network traffic, identifies sensitive data flows, and dynamically adjusts security policies without requiring static server groupings, thus maintaining both flexibility and security control
Solution Approach 2:
The security system dynamically adapts to changing network conditions by continuously monitoring traffic patterns and reconfiguring security policies in real-time. This allows the system to maintain reliable security control despite the dynamic nature of virtualized server deployments
2Productivity
If sensitive data is stored on compute servers rather than dedicated storage servers, then data processing efficiency is improved, but the complexity of securing and managing data locations increases
Solution Approach 1:
The security controller provides universal security management that works across multiple server types and data locations. It can identify and protect sensitive data regardless of whether it resides on compute servers, storage servers, or database servers, simplifying security management while maintaining processing efficiency
Solution Approach 2:
The system implements continuous feedback loops where the security controller monitors data flows, identifies sensitive information, and automatically adjusts security policies. This closed-loop approach reduces management complexity by automating the response to changing data locations and access patterns
3Adaptability or versatility
If data sharing is enabled among multiple servers, then collaboration and functionality are improved, but the risk of unauthorized access and data breaches increases
Solution Approach 1:
The patent applies differentiated security measures to different data flows and server interactions. Instead of uniform security restrictions, the system analyzes each data flow's sensitivity and applies appropriate security controls, enabling broad data sharing while protecting sensitive information from unauthorized access
Solution Approach 2:
The security controller acts as an intermediary that monitors and controls data sharing between servers. It identifies sensitive data flows and enforces access policies without preventing legitimate collaboration, thus maintaining both data sharing capability and protection against unauthorized access
Data Source
AI summary
Implementation of a secure network may be provided by analyzing packet traffic for sensitive information. Network processing elements found to be processing sensitive information may be classified as needing higher security. The classified network processing elements may be moved into a group of secure network processing elements.


