Public Cloud Expansion Through Authenticated Security Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of ensuring security in the process of expanding public clouds, particularly when deploying expanded available zones in user machine rooms, where the zones are at risk of tampering, cracking, and being used as attack vectors.

Innovation Solution

Implementing a security gateway in the public cloud to authenticate physical devices in the expanded available zone, establishing a secure tunnel, and managing the zone through a VPN tunnel to ensure secure communication and control, while integrating hardware facilities in a software-hardware manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the public cloud boundary is expanded by deploying expanded available zones in user machine rooms, then the service coverage and user accessibility are improved, but the security risk increases due to tampering, cracking, and attack vector possibilities

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A security gateway is introduced as an intermediary component between the expanded available zone and the public cloud. The gateway authenticates physical devices, establishes secure tunnels, and manages traffic flow, thereby enabling safe expansion without directly exposing the public cloud to security risks from user machine rooms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct zones: the public cloud, the expanded available zone in user machine rooms, and the security gateway in between. This segmentation isolates potential security threats in the expanded zone while maintaining controlled access to the public cloud infrastructure

Inventive Principle:
Principle #1Segmentation

2Reliability

If a security gateway is deployed to authenticate physical devices and establish secure tunnels, then the security and data integrity are improved, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway performs multiple functions including authentication, secure tunnel establishment, traffic management, and access control within a single unified component. This multi-functionality achieves comprehensive security without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If physical devices in the expanded available zone need to access public cloud services, then the functionality and usability are improved, but the security vulnerability increases due to potential tampering and cracking

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Physical devices must undergo authentication and establish secure tunnels before accessing public cloud services. This preliminary security check prevents unauthorized or tampered devices from accessing the cloud, enabling functionality while mitigating security vulnerabilities

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250294025A1Method for expanding public cloud, device, system, and storage medium
Publication Date: 2025.09.18 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US20250294025A1 patent drawing
  • US20250294025A1 patent drawing
  • US20250294025A1 patent drawing

AI summary

Embodiments of the present application provide a method for expanding a public cloud, a device, a system, and a storage medium. In the embodiments of the present application, an expanded available zone is created for the public cloud, and the expanded available zone is deployed in a user machine room, so that a hardware facility of the public cloud is deployed to the user machine room in a software-hardware integration manner, which can meet requirements of users for data security, data local processing, low latency, etc. By managing the expanded available zone into the public cloud, the users can locally have usage experience that is consistent with that of the public cloud, and a boundary of the public cloud is expanded.