Dynamic Security Service Chain for Data Center Packet Adaptability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security appliances struggle to provide customized and adaptive security services for data centers, especially in the context of Network Function Virtualization (NFV) and Service Function Chain (SFC), as they are hardware-based and fixed, failing to meet the diverse security requirements for data at rest, in use, and in transit effectively.
Innovation Solution
A method and apparatus for providing a security service in a data center by determining security labels for packets and selecting a Security Service Chain (SSC) based on these labels, which includes an ordered set of security functions to be applied, ensuring customized, dynamic, and adaptive security services for data in transit, at rest, and in use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional hardware-based security appliances are used, then security functions are stable and reliable, but the system cannot adapt to different security requirements for different data dynamically
Solution Approach 1:
The patent implements dynamic security service chains that can be flexibly configured and selected based on real-time security requirements of different data packets. The security functions are no longer fixed in hardware but are dynamically assigned through software-based service chains that adapt to varying security needs, resolving the contradiction between adaptability and complexity.
Solution Approach 2:
The system changes the security processing parameters by using labels to indicate different security requirements for different data types. This allows the security service chain to be selected and configured based on data-specific parameters rather than using a fixed security configuration for all data, enabling adaptability without requiring complete system redesign.
2Adaptability or versatility
If fixed-location security appliances are deployed, then implementation is simple, but they cannot provide customized security services for diverse data types
Solution Approach 1:
The patent creates a universal security service chain framework that can handle multiple types of data with different security requirements through a single system. The labeled packet mechanism and configurable service chains allow one system to perform multiple security functions for diverse data types, achieving customized security services without requiring separate fixed appliances for each data type.
Solution Approach 2:
The system introduces labels as an intermediary mechanism that carries security requirement information through the network. These labels enable the security service chain selection process to automatically match data with appropriate security treatments, providing customized security services while maintaining simple deployment through automated label-based routing.
3Reliability
If security services are made dynamic and flexible to meet different data requirements, then security effectiveness improves, but system complexity increases
Solution Approach 1:
The patent segments security services into discrete, modular security functions that can be independently configured and combined into service chains. This segmentation allows the system to provide detailed and effective security for different data types while managing complexity through modular design, where each security function is a self-contained unit that can be selectively applied based on data labels.
Data Source
Figure 1~3
Figure 4~6
Figure 7A~7C
AI summary
Embodiments of the present disclosure relate to a method, apparatus, and computer readable medium for providing a security service for a data center. According to the method, a packet terminating at or originating from the data center is received. At least one label is determined for the packet, each label indicating a security requirement for the packet. Based on the at least one label, a security service chain is selected for the packet, the security service chain including an ordered set of security functions deployed in the data center and to be applied to the packet. The packet is transmitted to the selected security service chain in association with the at least one label, the packet being processed by the ordered set of security functions in the security service chain.