Virtual Perimeter via Distributed Points of Presence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current industry standard 'fence-and-gate' approach for managing and securing distributed computer platforms across various geographic and ownership models is resource-intensive, expensive, and unsustainable, especially as more platforms and devices are added, as it relies on building separate perimeters for each instance, which is ineffective for managing mobile, remote, and home users and devices outside contained networks.

Innovation Solution

A network system with Perimeter Points of Presence (P/PoP) that provide a virtual perimeter, allowing for customized data processing and transmission policies across multiple service area systems, enabling parallel or serial data processing, and leveraging both physical and virtual connections for secure and compliant data flow management across diverse computing nodes and access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the fence-and-gate approach is used to control and secure each distributed computer platform instance separately, then security control is maintained for each individual platform, but the complexity and cost of managing multiple disparate perimeters increases significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate perimeter management systems into a single unified virtual perimeter that spans across all distributed computer platform instances. Instead of managing individual perimeters for each platform, the invention creates one consolidated perimeter policy that applies globally across data centers, public clouds, private clouds, and SaaS platforms, thereby reducing management complexity while maintaining security control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtual perimeter system provides universal security control that functions across diverse computing environments and access points. A single perimeter policy can be applied to multiple platform types including data centers, public clouds, private clouds, and SaaS platforms, as well as to various access methods such as office, remote, home, and mobile users, eliminating the need for separate perimeter configurations for each environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate perimeters are built for each computer platform instance, then control over each platform is maintained, but the resource intensity and cost of managing multiple perimeters becomes unsustainable

Engineering Contradiction:
Improveplatform controlVSAvoidresource intensity
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines multiple individual perimeter management resources into a single shared virtual perimeter infrastructure. By consolidating perimeter functions across all platform instances into one unified system, the resource intensity and cost of managing security perimeters is dramatically reduced while maintaining control over each platform through the centralized policy enforcement mechanism.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the fence-and-gate approach is used within contained networks, then security is maintained for devices within the network, but mobile, remote, and home users operating outside contained networks remain uncontrolled and exposed

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtual perimeter system provides universal security control that extends beyond traditional contained networks to encompass all access points including office, remote, home, and mobile users. The system adapts to diverse access scenarios by applying the same perimeter policy across different network environments and device types, maintaining security control while supporting flexible access methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9197601B2System and method for providing a single global borderless virtual perimeter through distributed points of presence
Publication Date: 2015.11.24 FORTINET INC
  • US9197601B2 patent drawing
  • US9197601B2 patent drawing
  • US9197601B2 patent drawing

AI summary

A system and method for providing a virtual perimeter through distributed points of presence. A network system comprises one or more Perimeter Points of Presence (P/PoP) configured to provide a virtual perimeter. The one or more P/PoPs comprise a network interface component; a plurality of selectable service area systems, each of which comprises one or more selectable service area sub-systems, wherein the selectable service area systems and sub-systems can provide a customized virtual perimeter for an entity. The one or more P/PoPs are configured to receive data; process the data using at least one of the service area systems and sub-systems configured as a data processing policy for the entity; and transmit the processed data as policy compliant data from the one or more P/PoP to an end destination.