Public Cloud Expansion Through Authenticated Security Gateways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of ensuring security in the process of expanding public clouds, particularly when deploying expanded available zones in user machine rooms, where the zones are at risk of tampering, cracking, and being used as attack vectors.
Innovation Solution
Implementing a security gateway in the public cloud to authenticate physical devices in the expanded available zone, establishing a secure tunnel, and managing the zone through a VPN tunnel to ensure secure communication and control, while integrating hardware facilities in a software-hardware manner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the public cloud boundary is expanded by deploying expanded available zones in user machine rooms, then the service coverage and user accessibility are improved, but the security risk increases due to tampering, cracking, and attack vector possibilities
Solution Approach 1:
A security gateway is introduced as an intermediary component between the expanded available zone and the public cloud. The gateway authenticates physical devices, establishes secure tunnels, and manages traffic flow, thereby enabling safe expansion without directly exposing the public cloud to security risks from user machine rooms
Solution Approach 2:
The system is segmented into distinct zones: the public cloud, the expanded available zone in user machine rooms, and the security gateway in between. This segmentation isolates potential security threats in the expanded zone while maintaining controlled access to the public cloud infrastructure
2Reliability
If a security gateway is deployed to authenticate physical devices and establish secure tunnels, then the security and data integrity are improved, but the system complexity increases
Solution Approach 1:
The security gateway performs multiple functions including authentication, secure tunnel establishment, traffic management, and access control within a single unified component. This multi-functionality achieves comprehensive security without proportionally increasing system complexity
3Ease of operation
If physical devices in the expanded available zone need to access public cloud services, then the functionality and usability are improved, but the security vulnerability increases due to potential tampering and cracking
Solution Approach 1:
Physical devices must undergo authentication and establish secure tunnels before accessing public cloud services. This preliminary security check prevents unauthorized or tampered devices from accessing the cloud, enabling functionality while mitigating security vulnerabilities
Data Source
AI summary
Embodiments of the present application provide a method for expanding a public cloud, a device, a system, and a storage medium. In the embodiments of the present application, an expanded available zone is created for the public cloud, and the expanded available zone is deployed in a user machine room, so that a hardware facility of the public cloud is deployed to the user machine room in a software-hardware integration manner, which can meet requirements of users for data security, data local processing, low latency, etc. By managing the expanded available zone into the public cloud, the users can locally have usage experience that is consistent with that of the public cloud, and a boundary of the public cloud is expanded.


