Virtual Asset Perimeter for Cloud Security Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional computing environment perimeters, such as firewalls, are less effective in protecting applications hosted in cloud computing environments and vulnerable to backdoor attacks, as they were designed for internal networks and lack adaptability to external hosting scenarios.
Innovation Solution
A virtual asset perimeter system that dynamically adjusts security by admitting and excluding assets based on physical, operational, and metadata characteristics, using a virtual perimeter module to enforce policies and assign roles for access privileges, creating a secure network of shared services and resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional computing environment perimeters (firewalls) are used to protect applications, then security protection is provided for applications hosted within private networks, but the protection becomes ineffective when applications are hosted in cloud computing environments external to the private network
Solution Approach 1:
The patent implements a dynamic perimeter system that automatically adjusts and reconfigures security boundaries based on real-time asset locations and cloud environment changes. The perimeter is no longer static but adapts dynamically to follow and protect assets regardless of their hosting location, whether on-premises or in cloud environments.
Solution Approach 2:
The patent transitions security from a network-centric dimensional approach to an asset-centric dimensional approach. Instead of protecting perimeters at network boundaries, the system creates security perimeters around individual assets or groups of assets, adding a new dimensional layer of protection that operates independently of network location.
2Reliability
If traditional computing environment perimeters are used, then some security protection is provided, but the perimeters are vulnerable to backdoor attacks and encourage users to enter and leave through network back doors
Solution Approach 1:
The patent introduces intermediary security agents that are deployed on individual assets rather than at network perimeters. These agents act as local security intermediaries that enforce policies directly at the asset level, preventing backdoor attacks by maintaining security controls regardless of how assets are accessed or where connections originate.
Solution Approach 2:
The system implements self-service security where assets automatically enforce their own security policies through deployed agents. Each asset becomes self-protecting, automatically detecting and responding to backdoor attempts without relying on external perimeter controls, thereby eliminating the vulnerability to backdoor attacks that plague traditional perimeter-based systems.
3Adaptability or versatility
If a virtual asset perimeter system dynamically admits and excludes assets based on characteristics, then security is enhanced and adaptability improves, but system complexity increases
Solution Approach 1:
The patent implements self-service automation where the system automatically evaluates asset characteristics, determines admission eligibility, and enforces security policies without manual intervention. The virtual perimeter system autonomously admits or excludes assets based on predefined criteria, reducing the operational complexity despite the sophisticated dynamic management capabilities.
Solution Approach 2:
The system manages complexity by changing key parameters from manual configuration to automated evaluation based on asset characteristics. Instead of requiring complex manual setup for each asset, the system dynamically adjusts security parameters based on automatically assessed asset properties, simplifying operations while maintaining high adaptability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method provides a virtual perimeter by maintaining a data structure for identifying a first plurality of assets, according to one embodiment. The system and method provides services to a second of the first plurality of assets, at least partially based on identifiers for the first plurality of assets and at least partially based on a first role assigned to a first of the first plurality of assets, according to one embodiment. The system and method include admitting one of a second plurality of assets into the virtual perimeter if characteristics of the one of the second plurality of assets satisfy criteria for admission to the virtual perimeter, according to on embodiment.