Dynamic Security Service Chain for Data Center Packet Adaptability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security appliances struggle to provide customized and adaptive security services for data centers, especially in the context of Network Function Virtualization (NFV) and Service Function Chain (SFC), as they are hardware-based and fixed, failing to meet the diverse security requirements for data at rest, in use, and in transit effectively.

Innovation Solution

A method and apparatus for providing a security service in a data center by determining security labels for packets and selecting a Security Service Chain (SSC) based on these labels, which includes an ordered set of security functions to be applied, ensuring customized, dynamic, and adaptive security services for data in transit, at rest, and in use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional hardware-based security appliances are used, then security functions are stable and reliable, but the system cannot adapt to different security requirements for different data dynamically

Engineering Contradiction:
Improveadaptability to different security requirementsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security service chains that can be flexibly configured and selected based on real-time security requirements of different data packets. The security functions are no longer fixed in hardware but are dynamically assigned through software-based service chains that adapt to varying security needs, resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security processing parameters by using labels to indicate different security requirements for different data types. This allows the security service chain to be selected and configured based on data-specific parameters rather than using a fixed security configuration for all data, enabling adaptability without requiring complete system redesign.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If fixed-location security appliances are deployed, then implementation is simple, but they cannot provide customized security services for diverse data types

Engineering Contradiction:
Improvecustomized security service capabilityVSAvoiddeployment simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal security service chain framework that can handle multiple types of data with different security requirements through a single system. The labeled packet mechanism and configurable service chains allow one system to perform multiple security functions for diverse data types, achieving customized security services without requiring separate fixed appliances for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces labels as an intermediary mechanism that carries security requirement information through the network. These labels enable the security service chain selection process to automatically match data with appropriate security treatments, providing customized security services while maintaining simple deployment through automated label-based routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security services are made dynamic and flexible to meet different data requirements, then security effectiveness improves, but system complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity service chain complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security services into discrete, modular security functions that can be independently configured and combined into service chains. This segmentation allows the system to provide detailed and effective security for different data types while managing complexity through modular design, where each security function is a self-contained unit that can be selectively applied based on data labels.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3750289B1Method, apparatus, and computer readable medium for providing security service for data center
Publication Date: 2024.04.03 NOKIA TECHNOLOGIES OY
  • EP3750289B1 patent drawingFigure 1~3
  • EP3750289B1 patent drawingFigure 4~6
  • EP3750289B1 patent drawingFigure 7A~7C

AI summary

Embodiments of the present disclosure relate to a method, apparatus, and computer readable medium for providing a security service for a data center. According to the method, a packet terminating at or originating from the data center is received. At least one label is determined for the packet, each label indicating a security requirement for the packet. Based on the at least one label, a security service chain is selected for the packet, the security service chain including an ordered set of security functions deployed in the data center and to be applied to the packet. The packet is transmitted to the selected security service chain in association with the at least one label, the packet being processed by the ordered set of security functions in the security service chain.