Appliance Security Wrapping in Cloud Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, users are concerned about the security of applications and appliances hosted on third-party resources, as the cloud provider cannot guarantee the security of these resources, leading to hesitation in utilizing cloud services.

Innovation Solution

Implementing a secure rights application that 'wraps' appliances in a security container, limiting access and encrypting components, while allowing normal operation, and using an access record and authentication server to manage user access, enabling originators to control and secure their appliances independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If appliances are hosted on third-party cloud resources, then cloud computing scalability and accessibility are improved, but security control and reliability deteriorate

Engineering Contradiction:
Improvecloud computing scalabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cloud infrastructure into trusted cloud resources (managed by the cloud provider) and untrusted cloud resources (third-party resources). The appliance is designed to operate on untrusted resources while maintaining security through virtualization and isolation mechanisms, allowing scalable deployment without compromising security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security intermediary layer (virtual machine monitor/hypervisor) that sits between the appliance and the untrusted cloud resources. This intermediary enforces security policies, controls access to sensitive operations, and isolates the appliance from potentially malicious third-party resources, resolving the contradiction between scalability and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud providers use third-party computing systems to expand resource pool, then resource availability and scalability are improved, but security guarantee capability deteriorates

Engineering Contradiction:
Improveresource availabilityVSAvoidsecurity guarantee
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by making the appliance itself security-conscious rather than relying on the cloud provider's security guarantees. The appliance incorporates built-in security measures and is designed to secure itself when running on untrusted resources, allowing the cloud provider to expand resources without compromising security guarantees.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The appliance performs self-service security functions by automatically securing itself against threats from untrusted third-party resources. This self-securing capability allows the cloud provider to freely allocate resources without needing to verify or guarantee the security of each third-party system, thus improving resource availability while maintaining security guarantees.

Inventive Principle:
Principle #25Self-service

3Reliability

If users want to ensure security of their appliances, then security control is improved, but ease of using cloud services deteriorates

Engineering Contradiction:
Improveappliance securityVSAvoidcloud service usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring the appliance with security mechanisms before deployment to the cloud. The appliance is designed and secured in advance, incorporating security policies and protections that automatically activate when the appliance is instantiated on untrusted cloud resources, eliminating the need for users to manually configure security settings and simplifying cloud service usage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9210173B2Securing appliances for use in a cloud computing environment
Publication Date: 2015.12.08 RED HAT INC
  • US9210173B2 patent drawing
  • US9210173B2 patent drawing
  • US9210173B2 patent drawing

AI summary

An originator of an appliance can independently secure the appliance for instantiation in the cloud, separate from the security level of the cloud. The originator can secure the appliance utilizing a secure rights application. The secure rights application can be configured to “wrap” an appliance in a security container. The security container can limit access to the applications and operating systems contained in the appliance, but allow the appliance to operate normally once instantiated in the cloud. The secure rights application can be configured to cryptographically secure the appliance in order limit the ability of unauthorized parties from accessing the components of the appliance while maintaining the functionality of the appliance.