Virtual Network Segmentation for SaaS Security and Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Software as a Service (SaaS) models face limitations in application independence, security, data sharing, customization, and maintenance due to monolithic application servers, which lead to integration difficulties, security concerns, and increased maintenance costs.

Innovation Solution

A centralized management system utilizing a computer data grid with a virtualization platform, grid access security layer, virtual computer network template system, resource distribution tools, and monitoring and metering tools to create, deploy, and manage separate and distinct virtual computer networks, allowing for independent management and customization of each network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a monolithic application server is used to deliver SaaS applications, then maintenance and management costs are reduced through commoditization, but security is compromised and application independence is lost

Engineering Contradiction:
Improvemaintenance costVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the monolithic application server into multiple isolated virtual computer networks, each hosting specific SaaS applications. This segmentation allows individual networks to be secured independently while maintaining overall system manageability through the virtualization platform, thus resolving the contradiction between reduced maintenance costs and compromised security.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a monolithic application server is used to deliver SaaS applications, then management overhead is reduced, but application independence and customization are lost

Engineering Contradiction:
Improvemanagement overheadVSAvoidapplication independence
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The virtualization platform provides universal management capabilities that can handle multiple virtual computer networks simultaneously. This allows the system to maintain low management overhead through automated provisioning and monitoring while enabling each virtual network to host independent, customized SaaS applications, thus resolving the contradiction between management ease and application independence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If data is stored in a shared database with user name and password controls, then storage efficiency is improved, but security is compromised due to potential commingling and unauthorized access

Engineering Contradiction:
Improvestorage efficiencyVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the shared database into separate, isolated databases for each virtual computer network. This segmentation maintains storage efficiency by consolidating data at the infrastructure level while enhancing security by preventing unauthorized access between networks through the isolation provided by the virtualization platform.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If third party tools are used for data sharing between applications, then application integration is enabled, but system complexity increases and maintenance becomes difficult

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the data sharing functionality into the virtualization platform itself, allowing applications within the same virtual computer network to share data through controlled mechanisms. This eliminates the need for separate third-party integration tools, reducing system complexity while maintaining data sharing capabilities through the unified management interface.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11032178B2System and method for creating, deploying, and administering distinct virtual computer networks
Publication Date: 2021.06.08 WEINBERG BRIAN
  • US11032178B2 patent drawing
  • US11032178B2 patent drawing
  • US11032178B2 patent drawing

AI summary

Embodiments of the invention relate to a centralized managing system and method for creating, deploying, administering, and managing a plurality of separate and distinct virtual computer networks on a virtualization platform for offering cloud computing services (SaaS). Embodiments of the invention relate to a computer system for a centralized management of separate and distinct virtual computer networks, which has a security grid which has at least one grid processor and a memory device that stores a managing application. The managing application has a virtualization platform, a grid access layer, a virtual computer network template system, a plurality of resource distribution tools and a plurality of monitoring and metering tools. The grid processor is adapted by the managing application so that it can create, deploy, administer, and manage the plurality of separate and distinct computer networks.