IP Library › Granted Patent US 11,652,847
Granted Patent B2
US 11,652,847 · App. 16/147,934 · Granted May 16, 2023

Decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment

Inventors: William A. O'Hern (Spring Lake, NJ); Edward G. Amoroso (Andover, NJ); Michelle Barry (Odessa, FL); Anthony Ramos (Gainesville, VA); Daniel Solero (Mooresville, IN); Duncan Kirkwood Sparrell (Oakton, VA); Rodney Dilts (West River, MD)
Assignee: KYOCERA Corporation
H04L63/20G06F9/45558H04L63/10H04W12/08H04W12/37G06F2009/4557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,847
App. No.
16/147,934
Granted
May 16, 2023
Kind
B2
Abstract

Concepts and technologies are disclosed herein for decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment. A computer system includes a processor that can execute computer-executable instructions to perform various operations. The processor can perform operations to provide security services to one or more customer platforms. The operations can include receiving a network security software component from a security service provider, and deploying the network security software component within a distributed computing environment so that the network security software component can be executed by a computing resource of the distributed computing environment to provide a security service to the customer platform(s). The network security software component includes a software component that has been decoupled from a hardware component of a network security device by the security service provider.

Claims (41)

1. A cloud computing system comprising:

at least one processor; and

a memory coupled to the at least one processor, the at least one processor configured to perform operations comprising:

deploying a network security software within a virtualized network of the cloud computing system so that the network security software can be executed by a computing resource deployed within the virtualized network to provide a security service on the virtualized network, wherein the network security software has been decoupled from a hardware of a network security device;

receiving an application programming interface (API) call from a customer platform device external to the virtualized network, the API call requesting to provide the security service on identified asset of a plurality of assets in a customer platform asset within the virtualized network; and

in response to receiving the API call, executing the network security software by the computing resource deployed within the virtualized network to provide the security service on the identified asset within the virtualized network.

2. The cloud computing system of claim 1 , wherein the operations further comprise:

exposing, to the customer platform device, an API to provide access to the security service provided by the network security software.

3. The cloud computing system of claim 1 , wherein the computing resource used to execute the network security software includes at least one virtual machine.

4. The cloud computing system of claim 1 , wherein the API call includes a request for the security service.

5. The cloud computing system of claim 1 , wherein in response to receiving the API call, the at least one processor provides the security service to a virtualized asset deployed within the virtualized network.

6. The cloud computing system of claim 5 , wherein the security service is a firewall that provides firewall protection to the virtualized asset.

7. A cloud computing method comprising:

deploying a network security software within a virtualized network so that the network security software can be executed by a computing resource deployed within the virtualized network to provide a security service on the virtualized network, wherein the network security software has been decoupled from a hardware of a network security device;

receiving an application programming interface (API) call from a customer platform device external to the virtualized network, the API call requesting to provide the security service on identified asset of a plurality of assets in a customer platform asset within the virtualized network; and

in response to receiving the API call, executing the network security software by the computing resource deployed within the virtualized network to provide the security service on the identified asset within the virtualized network.

8. A system comprising at least one hardware computing resource upon which instructions are stored that, when executed, cause the hardware computing resource to perform operations comprising:

configuring a virtual machine to support a security service on a virtualized network;

instantiating the virtual machine on the hardware computing resource;

receiving an application programming interface (API) call from a customer platform device external to the virtualized network, the API call requesting to provide the security service on identified asset of a plurality of assets in a customer platform asset within the virtualized network; and

in response to receiving the API call, executing a network security software deployed within the virtualized network by the virtual machine instantiated on the hardware computing resource deployed within the virtualized network to provide the security service on the identified asset within the virtualized network, wherein the network security software has been decoupled from a hardware of a network security device.

9. The system of claim 8 , wherein the operations further comprise:

exposing, to the customer platform device, an (API) to provide access to the security service.

10. The system of claim 8 , wherein the hardware computing resource is a part of a distributed computing environment comprising a plurality of hardware computing resources.

11. The system of claim 8 , wherein in response to receiving the API call, the security service is provided to a virtualized asset deployed within the virtualized network.

12. The system of claim 11 , wherein the security service is a firewall that provides firewall protection to the virtualized asset.

13. The system of claim 8 , wherein

the API call identifies a virtualized asset within the virtualized network and instructs that the security service be provided to the virtualized asset.

14. The cloud computing system of claim 1 , wherein

the API call identifies a virtualized asset within the virtualized network and instructs that the security service be provided to the virtualized asset.

15. The cloud computing method of claim 7 , wherein

in response to receiving the API call, the security service is provided to a virtualized asset deployed within the virtualized network.

16. The cloud computing method of claim 15 , wherein the security service is a firewall that provides firewall protection to the virtualized asset.

17. The cloud computing method of claim 7 , wherein

the API call identifies a virtualized asset within the virtualized network and instructs that the security service be provided to the virtualized asset.

18. The cloud computing system of claim 1 , wherein

the receiving of the API call is at the at least one processor of the cloud computing system.

19. The cloud computing method of claim 7 , wherein

the receiving of the API call is at least one processor of a cloud computing system.

20. The system of claim 8 , wherein

the receiving of the API call is at least one processor of a cloud computing system.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: AT&T INTELLECTUAL PROPERTY I, L.P.
To: KYOCERA CORPORATION
Reel/Frame 052563/0220 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2018
From: O'HERN, WILLIAM A.; AMOROSO, EDWARD G.; BARRY, MICHELLE; RAMOS, ANTHONY; SOLERO, DANIEL; SPARRELL, DUNCAN KIRKWOOD
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 047015/0403 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2018
From: DILTS, RODNEY
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 047171/0643 →
Continuity (3)
Continuation 15276225 · Sep 26, 2016
Continuation 13949695 · Jul 24, 2013
Related Publication 20190036974A1 · Jan 31, 2019