Dynamically Reconfigurable Virtual Environment for Secure Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for securely exchanging information among multiple stakeholders are limited by the need for physical separation of hardware components, which restricts the realization of cloud computing efficiencies in software-defined networks and data centers due to physical separation requirements for secure cryptographic network information sharing.
Innovation Solution
A system comprising multiple server computing devices with non-transitory computer-readable storage media and processors to establish and manage logically separate and secure networks within a self-supported computing environment, enabling dynamic reconfiguration and secure data separation without requiring physical separation of hardware components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical separation of hardware components is used for secure cryptographic network information sharing, then security is improved, but cloud computing efficiencies and resource utilization are worsened
Solution Approach 1:
The patent applies segmentation by dividing the network into multiple logically separate virtual networks (e.g., military, intelligence, diplomatic networks) that are isolated through software-defined networking. This allows secure information sharing while enabling efficient resource utilization across the entire virtualized infrastructure, resolving the contradiction between security through physical separation and cloud computing efficiencies.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between physical hardware and network traffic. This virtualization layer (including virtual switches, routers, and firewalls) provides cryptographic separation and network security while allowing multiple networks to share the same physical infrastructure, thereby achieving both security and resource efficiency.
2Reliability
If physical separation of hardware components is required for secure networks, then security is improved, but device complexity and hardware requirements are worsened
Solution Approach 1:
The patent replaces the mechanical/physical separation system with a software-based virtualization system. Instead of physically separating hardware components for different networks, the system uses virtualization software to create logically separate networks that are isolated through cryptographic protocols and virtual networking layers, thereby reducing hardware complexity while maintaining security.
Solution Approach 2:
The patent implements a universal virtualized infrastructure that can host multiple secure networks simultaneously on the same hardware platform. This multi-functional system allows a single physical server to support multiple virtual networks (military, intelligence, diplomatic) with different security requirements, eliminating the need for separate dedicated hardware for each network.
3Adaptability or versatility
If additional hardware components are added to support multiple secure networks, then network capacity is improved, but system cost and resource utilization are worsened
Solution Approach 1:
The patent merges multiple secure networks onto a single shared infrastructure through virtualization. Instead of having separate physical hardware for each network, the system combines military, intelligence, and diplomatic networks into a unified virtualized platform that allocates resources dynamically, thereby reducing the total quantity of hardware components needed while maintaining multi-network capability.
Solution Approach 2:
The patent implements dynamic resource allocation where hardware resources (CPU, memory, storage, network bandwidth) can be dynamically assigned and reassigned to different virtual networks based on demand. This dynamic virtualized infrastructure allows the system to adapt to varying network requirements without requiring permanent dedicated hardware for each network, optimizing resource utilization.
Data Source
AI summary
The present disclosure relates to a system, comprising: a first server computing device configured to store various application data relating to the system, and control a first plurality of modules to simultaneously establish multiple logically separate and secure networks within a self-supported computing environment; a second server computing device configured to control a second plurality of modules to perform out-of-band management of the system; and a third server computing device configured to control a third plurality of modules to control inbound and outbound data traffic of the logically separate and secure networks. The system is scalable by at least adding additional one or more first server computing devices to host additional application data within the self-supported computing environment's secure configuration and logical separation of networks while maintaining the second and third server computing devices.


