Virtualized Network Gateway for Scalable Security Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions rely on expensive hardware that is difficult to configure and maintain, and do not automatically scale with demand or threat levels, leading to productivity disruptions and inefficiencies.
Innovation Solution
A system that provides network connectivity and related services through scalable computing resources, allowing customer entities to access network services via a computing resource provider, which implements and manages network-related services such as DDoS protection, firewalling, and spam control using programmable APIs and interfaces, enabling intelligent provisioning, scaling, and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based network security appliances are deployed to protect against threats, then network security is improved, but device cost and complexity increase
Solution Approach 1:
The patent replaces physical hardware security appliances with virtualized security functions implemented as software services on general-purpose computing infrastructure. Network security functions such as firewalling, intrusion detection, and threat protection are delivered as virtual network functions (VNFs) that can be deployed, configured, and managed through software without requiring dedicated hardware devices.
Solution Approach 2:
The patent creates a universal security platform that can provide multiple security functions simultaneously on shared infrastructure. A single computing resource pool can host various security services (firewall, IDS/IPS, anti-spam, DDoS protection) that can be dynamically allocated to different customer entities, eliminating the need for separate hardware appliances for each security function.
2Reliability
If dedicated hardware security appliances are deployed, then network security protection is improved, but ease of operation and maintenance deteriorates
Solution Approach 1:
The patent implements self-service capabilities where customer entities can automatically provision, configure, and manage security services through software interfaces without requiring specialized hardware knowledge. The virtualized platform enables automated service deployment, dynamic configuration updates, and self-healing mechanisms that eliminate manual hardware intervention.
Solution Approach 2:
The patent introduces a software-based intermediary layer (virtualization platform and service management system) between the customer entities and the underlying computing infrastructure. This intermediary abstracts the complexity of security service deployment and management, providing simplified interfaces while handling the intricate configuration and coordination of security functions.
3Reliability
If hardware-based security solutions are implemented, then network threat protection is improved, but adaptability to changing demands and threats deteriorates
Solution Approach 1:
The patent implements dynamic security services that can automatically scale their computational resources based on real-time threat levels and demand. The virtualized platform monitors network conditions and dynamically allocates computing, storage, and networking resources to security functions, enabling seamless scaling up during attacks and scaling down during normal operations.
Solution Approach 2:
The patent enables dynamic adjustment of security service parameters such as processing capacity, inspection depth, and resource allocation without requiring hardware changes. The software-based implementation allows parameters like throughput capacity, concurrent connection limits, and security policy complexity to be modified on-the-fly to match changing network conditions and threat landscapes.
Data Source
AI summary
A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.


