Secure Resource Provisioning via Temporary Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for provisioning resources from a trusted network to an untrusted network are either complex and difficult to implement or allow unauthorized access, as they often require direct connectivity between the networks, which can be exploited by malicious users.

Innovation Solution

A resource provisioning system creates a temporary network that interacts with the trusted network to provision resources without direct connectivity between the trusted and untrusted networks, using a control plane to manage network topology and ensure secure access by disconnecting the trusted network from the temporary network before connecting it to the untrusted network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct connectivity is established between trusted network and untrusted network for resource provisioning, then resource access is enabled, but security is compromised allowing unauthorized access

Engineering Contradiction:
Improveresource accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A temporary network is introduced as an intermediary between the trusted network and untrusted network. The temporary network receives resources from the trusted network and provides them to the untrusted network without establishing direct connectivity between the two networks, thus maintaining security while enabling resource access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity increases making implementation difficult

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network architecture is segmented into distinct components: trusted network, temporary network, and untrusted network. This segmentation isolates security functions to specific boundaries rather than requiring complex access control mechanisms throughout the entire network, simplifying implementation while maintaining security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If zero trust networks with multiple components are used to ensure authenticated access, then security is improved, but implementation complexity increases

Engineering Contradiction:
ImproveauthenticationVSAvoidmultiple components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication and security functions are extracted and concentrated at the boundary between the trusted network and temporary network. This allows the temporary network to provide simplified access control to the untrusted network without requiring multiple complex components throughout the entire architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11632372B2Provisioning resources for access by an untrusted computer network
Publication Date: 2023.04.18 SALESFORCE INC
  • US11632372B2 patent drawing
  • US11632372B2 patent drawing
  • US11632372B2 patent drawing

AI summary

A system securely provisions a resource for access by computing systems of an untrusted network. The provisioning is performed securely such that at no stage during the process the computing systems of the untrusted network have direct access to the computing systems of the trusted network. The system creates a temporary network connected to the trusted network and provisions the requested resource in the temporary network. The system connects the temporary network to the trusted network for provisioning of the resource. The system disconnects the trusted network from the temporary network before connecting the untrusted network to the temporary network for providing access to the resource.