Private Native Security Groups in Public Cloud Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud solutions often require agents to be installed on workload virtual machines for private cloud capabilities in public clouds, which can be cumbersome and violate compliance requirements, and users seek a common policy across public and on-premises environments without agents.

Innovation Solution

A system and method using private native security groups and private native firewall policy rules, where a public cloud gateway routes data traffic between private and public cloud environments, creating cloud native security group rule objects to enable the use of these rules in the cloud network, allowing for agentless deployment and compliance with compliance requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If agents are installed on workload virtual machines to enable private cloud capabilities in public cloud, then private cloud functionality is achieved, but deployment complexity and compliance issues increase

Engineering Contradiction:
Improveprivate cloud capabilityVSAvoidagent installation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the agent component from the solution and replaces it with native cloud security groups and firewall policy rules. By removing the agent requirement and using only cloud-native resources, the solution achieves private cloud capabilities without the complexity and compliance issues of agent installation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud gateway as an intermediary component that enables policy enforcement and private cloud functionality without requiring agents on workload VMs. The gateway acts as a mediator between the public cloud infrastructure and private cloud requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If agents are installed on workload virtual machines, then private cloud control is achieved, but lifecycle management becomes cumbersome

Engineering Contradiction:
Improvecontrol capabilityVSAvoidlifecycle management
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent removes agents from the architecture entirely, replacing them with cloud-native security groups and firewall rules that are managed through standard cloud interfaces. This eliminates the time-consuming lifecycle management of agents while maintaining control capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The solution uses cloud-native resources that automatically manage themselves without requiring external agents. Security groups and firewall rules are self-managing through cloud infrastructure, eliminating manual lifecycle management overhead.

Inventive Principle:
Principle #25Self-service

3Reliability

If agents are mandated for cloud solution deployment, then security policy enforcement is improved, but compliance requirements may be violated

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidcompliance compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the security enforcement mechanism from agent-based implementation and implements it using cloud-native security groups and firewall rules. This approach maintains security policy enforcement capability while improving compliance compatibility by eliminating agents that may violate compliance requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If cloud native security group rule objects are created and updated, then private native firewall policy rules can be used in cloud network, but system complexity increases

Engineering Contradiction:
Improvepolicy compatibilityVSAvoidrule object management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates cloud native security group rule objects that serve multiple purposes: they enable private native firewall policy rules to function in the cloud network while also providing standard cloud-native security management. This multi-functional approach achieves policy compatibility without excessive complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11831610B2System and method for using private native security groups and private native firewall policy rules in a public cloud
Publication Date: 2023.11.28 VMWARE INC
  • US11831610B2 patent drawing
  • US11831610B2 patent drawing
  • US11831610B2 patent drawing

AI summary

A system and method for using private native security groups and private native firewall policy rules for a private cloud computing environment and a public cloud computing environment uses a public cloud gateway for routing data traffic between at least a cloud network created in the public cloud computing environment and the private cloud computing environment. For each of some private native firewall policy rules that has any of newly created private native security groups as one of source and destination, a cloud native security group (CNSG) rule object with an CNSG outbound rule object and an CNSG inbound rule object for the public cloud is created and at least one of the CNSG outbound rule object and the CNSG inbound rule object is updated so that the private native firewall policy rule can be used in the cloud network.