Virtual Network Segmentation for SaaS Security and Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Software as a Service (SaaS) models face limitations in application independence, security, data sharing, customization, and maintenance due to monolithic application servers, which lead to integration difficulties, security concerns, and increased maintenance costs.
Innovation Solution
A centralized management system utilizing a computer data grid with a virtualization platform, grid access security layer, virtual computer network template system, resource distribution tools, and monitoring and metering tools to create, deploy, and manage separate and distinct virtual computer networks, allowing for independent management and customization of each network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a monolithic application server is used to deliver SaaS applications, then maintenance and management costs are reduced through commoditization, but security is compromised and application independence is lost
Solution Approach 1:
The patent segments the monolithic application server into multiple isolated virtual computer networks, each hosting specific SaaS applications. This segmentation allows individual networks to be secured independently while maintaining overall system manageability through the virtualization platform, thus resolving the contradiction between reduced maintenance costs and compromised security.
2Ease of operation
If a monolithic application server is used to deliver SaaS applications, then management overhead is reduced, but application independence and customization are lost
Solution Approach 1:
The virtualization platform provides universal management capabilities that can handle multiple virtual computer networks simultaneously. This allows the system to maintain low management overhead through automated provisioning and monitoring while enabling each virtual network to host independent, customized SaaS applications, thus resolving the contradiction between management ease and application independence.
3Quantity of substance
If data is stored in a shared database with user name and password controls, then storage efficiency is improved, but security is compromised due to potential commingling and unauthorized access
Solution Approach 1:
The patent segments the shared database into separate, isolated databases for each virtual computer network. This segmentation maintains storage efficiency by consolidating data at the infrastructure level while enhancing security by preventing unauthorized access between networks through the isolation provided by the virtualization platform.
4Adaptability or versatility
If third party tools are used for data sharing between applications, then application integration is enabled, but system complexity increases and maintenance becomes difficult
Solution Approach 1:
The patent merges the data sharing functionality into the virtualization platform itself, allowing applications within the same virtual computer network to share data through controlled mechanisms. This eliminates the need for separate third-party integration tools, reducing system complexity while maintaining data sharing capabilities through the unified management interface.
Data Source
AI summary
Embodiments of the invention relate to a centralized managing system and method for creating, deploying, administering, and managing a plurality of separate and distinct virtual computer networks on a virtualization platform for offering cloud computing services (SaaS). Embodiments of the invention relate to a computer system for a centralized management of separate and distinct virtual computer networks, which has a security grid which has at least one grid processor and a memory device that stores a managing application. The managing application has a virtualization platform, a grid access layer, a virtual computer network template system, a plurality of resource distribution tools and a plurality of monitoring and metering tools. The grid processor is adapted by the managing application so that it can create, deploy, administer, and manage the plurality of separate and distinct computer networks.


