Provisioning Physical Security Appliances in Virtualized Edge Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers using conventional technologies lack the ability to provision and configure network appliances from a range of hardware security appliance types, especially in service provider environments where physical hardware is virtualized, making it difficult to model or find hardware solutions similar to local options within the virtual environment, and they struggle with defining policy enforcement points and testing security configurations without disrupting production networks.

Innovation Solution

The technology enables customers to provision and configure physical security appliances at the edge of their virtual infrastructure within a service provider environment, allowing for hardware-accelerated options and elastic border security services, using APIs for management, and providing a platform to select and configure security appliances for specific security policies and packet paths, enabling on-demand access to purpose-built security hardware or virtual appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical security appliances are virtualized in a service provider environment, then customers can access security services in virtualized infrastructure, but customers lose the ability to provision and configure specific hardware security appliance types

Engineering Contradiction:
Improveaccess to security servicesVSAvoidability to provision and configure appliances
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates virtual representations (virtual machines) of physical security appliances that replicate their functionality and configuration interfaces. Customers can provision and configure these virtual appliances through web portals and APIs just as they would physical devices, while the actual security enforcement occurs on the physical hardware in the service provider's data center.

Inventive Principle:
Principle #26Copying

2Quantity of substance

If security appliances are deployed in virtualized environments, then customers can share infrastructure resources, but it becomes difficult to model and test security configurations without disrupting production networks

Engineering Contradiction:
Improveinfrastructure sharingVSAvoidtesting security configurations
Core Design Contradiction:
Quantity of substanceVSEase of manufacture

Solution Approach 1:

The patent enables customers to provision and test security appliance configurations in the virtualized environment before deploying them to production. The virtual appliances can be configured, tested, and validated in a safe sandbox environment that mirrors the production network topology, allowing customers to prepare security policies and rules without risking disruption to actual production networks.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If physical security appliances are made available in service provider environments, then customers gain access to purpose-built security hardware, but the device complexity and provisioning difficulty increase

Engineering Contradiction:
Improveaccess to purpose-built hardwareVSAvoidprovisioning complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service portals and automated APIs that allow customers to independently provision, configure, and manage their own security appliances without requiring service provider intervention. The system automatically handles appliance deployment, network integration, and configuration based on customer specifications, reducing the complexity burden on both customers and providers.

Inventive Principle:
Principle #25Self-service

4Loss of energy

If security appliances are virtualized and managed remotely, then service provider can reduce costs associated with local appliance deployment, but the reliability and security of remote management must be maintained

Engineering Contradiction:
Improvedeployment costsVSAvoidremote management security
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent introduces multiple layers of security intermediaries including virtualization hypervisors, security management platforms, and encrypted communication channels that mediate between the remote service provider and the physical security appliances. These intermediaries ensure that remote provisioning and management operations maintain the same security and reliability standards as local deployment, while still enabling cost-effective centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10484331B1Security appliance provisioning
Publication Date: 2019.11.19 AMAZON TECH INC
  • US10484331B1 patent drawing
  • US10484331B1 patent drawing
  • US10484331B1 patent drawing

AI summary

A technology is provided for security appliance provisioning. In one example, a method includes providing a variety of types of physical security appliances in a service provider environment. A selection may be received identifying a selected security appliance from among the variety of types of physical security appliances for use in a customer virtual infrastructure within the service provider environment. The selected security appliance may be provisioned for use at an edge location of the customer virtual infrastructure. The selected security appliance may be configured to enforce a security policy defined for the customer virtual infrastructure.