Secure Appliance for Cloud Application Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to provide a comprehensive and scalable security and management framework for applications in Infrastructure-as-a-Service (IaaS) cloud environments, leading to vulnerabilities and increased risk due to the lack of a perimeter security model and reliance on cloud providers for security measures.

Innovation Solution

A secure appliance is introduced, comprising a policy enforcement point (PEP) and a hardened operating system, which provides a secure baseline for applications, restricts communication, and offers fine-grained policy control, visibility into application state, and rapid scaling, allowing application owners to manage security and communications within a multi-tenant cloud environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If applications are deployed directly in IaaS cloud environments, then scalability and cloud benefits are improved, but security and management control deteriorate due to lack of perimeter security model

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a secure appliance as an intermediary component between the cloud environment and applications. This appliance contains a hardened operating system and policy enforcement point, serving as a perimeter security model within the cloud. It mediates security functions while allowing applications to maintain cloud scalability, thus resolving the contradiction between security control and cloud benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional perimeter security models are applied to each individual application, then security control is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure appliance is designed as a universal platform that can host multiple applications while providing centralized security control. The single hardened operating system and policy enforcement point serve multiple applications simultaneously, reducing deployment complexity compared to implementing separate security infrastructures for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the hardened operating system, policy enforcement point, and multiple applications into a single secure appliance. This merging approach consolidates security functions and simplifies deployment while maintaining individual application security requirements.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If cloud providers manage all security measures, then ease of operation is improved, but security reliability deteriorates due to lack of application owner control

Engineering Contradiction:
Improveoperation simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments security responsibilities between the cloud provider and application owner. The secure appliance provides a hardened operating system and infrastructure security managed by the application owner, while cloud providers manage the underlying cloud infrastructure. This segmentation allows application owners to maintain security control and reliability while benefiting from cloud operation simplicity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9531753B2Protected application stack and method and system of utilizing
Publication Date: 2016.12.27 CA TECH INC
  • US9531753B2 patent drawing
  • US9531753B2 patent drawing
  • US9531753B2 patent drawing

AI summary

A secure appliance for use within a multi-tenant cloud computing environment which comprises: a) a policy enforcement point (PEP); b) a hardened Operating System (OS) capable of deploying applications; and c) at least one application capable of hosting services and application program interfaces (APIs).