Pluggable Cloud Security System for Legacy Application Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing technologies face challenges in efficiently and securely scaling legacy applications without requiring changes to underlying code, leading to resource wastage and security vulnerabilities.

Innovation Solution

A pluggable cloud security system that uses nodes with processors and memory to enforce rules for data communication between user applications and cloud-hosted applications, preventing invalid data and scaling resources automatically to conserve processing and memory resources while enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-hosted applications are exposed to all user applications without filtering, then accessibility and ease of operation are improved, but security vulnerabilities and resource wastage increase

Engineering Contradiction:
Improveaccessibility of cloud-hosted applicationsVSAvoidsecurity vulnerabilities and resource wastage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud security system as an intermediary layer between user applications and cloud-hosted applications. This mediator evaluates incoming requests against stored rules, determining whether to allow or block communication based on source identification, channel validation, and criteria matching. This resolves the contradiction by maintaining open accessibility while filtering out harmful requests through the intermediary security layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If resources are allocated to handle all incoming communications, then service reliability is improved, but processing and memory resource consumption increase

Engineering Contradiction:
Improveservice reliability of cloud-hosted applicationsVSAvoidprocessing and memory resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The cloud security system performs preliminary evaluation of incoming requests before they reach the cloud-hosted applications. By pre-evaluating source identification, channel validity, and rule criteria matching, the system blocks invalid or malicious requests in advance. This prevents wasteful consumption of processing and memory resources on requests that would ultimately be rejected, while maintaining service reliability for legitimate requests.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If legacy applications are deployed without code modifications, then ease of manufacture and deployment are improved, but security and resource efficiency deteriorate

Engineering Contradiction:
Improvedeployment simplicity of legacy applicationsVSAvoidsecurity risks and resource inefficiency
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements a security intermediary that sits between user applications and legacy cloud-hosted applications without requiring any modifications to the legacy application code. The security system independently performs source identification, channel validation, and rule-based filtering, thereby protecting legacy applications from security risks and resource inefficiency while maintaining their original deployment simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If all communication channels are allowed to access cloud infrastructure, then adaptability and versatility are improved, but identification of malicious attacks and resource overload worsen

Engineering Contradiction:
Improvecommunication flexibilityVSAvoiddetection of malicious attacks and capacity overload
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The cloud security system implements feedback mechanisms by continuously monitoring incoming requests, evaluating them against stored rules, and adjusting its filtering decisions based on the evaluation results. The system provides feedback on source identification validity, channel authentication status, and rule criteria matching, enabling effective detection of malicious attacks and resource overload conditions while maintaining flexible communication channels for legitimate traffic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11882057B2Pluggable cloud security system
Publication Date: 2024.01.23 BANK OF AMERICA CORP
  • US11882057B2 patent drawing
  • US11882057B2 patent drawing
  • US11882057B2 patent drawing

AI summary

A pluggable cloud security system includes a plurality of nodes. Each node has a memory and a processor. At least one memory is configured to store rules indicating criteria for allowing communication between user applications and a hosted application executed by a cloud infrastructure. At least one processor is configured to receive data to be communicated to the cloud application, determine a source of the received data as a first user application, determine a channel used to transmit the received data, and determine, using the rules, whether the source and the channel satisfy criteria for allowing communication between the first user application and the hosted application. If it is determined that the source satisfies the first criteria, transmission of the data is allowed. Otherwise, transmission of the data is prevented.