Automated Security Provisioning for Virtual Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual process of deploying virtual applications into security groups in SDN systems is time-consuming and error-prone, necessitating an automated solution for security provisioning.

Innovation Solution

A method and system for automating security provisioning by determining the owner of a virtual application and assigning its workload to a security container or sub-container based on predefined security policies, using a cloud management tool and cloud security orchestration system across multiple clouds, ensuring automated and efficient security policy application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual administrative deployment of virtual applications into security groups is used, then security policies can be applied, but the process is time-consuming and error-prone

Engineering Contradiction:
Improveaccuracy of security policy applicationVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the virtualization environment automatically determines workload ownership and assigns appropriate security policies without requiring manual administrative intervention. The metamodel framework autonomously maps workloads to security groups based on ownership criteria, eliminating human error and accelerating deployment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The metamodel framework is pre-configured with security group definitions and ownership criteria before workload deployment. This preliminary setup enables automatic, accurate assignment of security policies during workload creation or migration, preventing errors before they occur and reducing deployment time.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated security provisioning is implemented, then deployment efficiency increases, but system complexity increases

Engineering Contradiction:
Improvedeployment speedVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The metamodel framework serves multiple functions: it defines security groups, determines workload ownership, maps workloads to security groups, and enforces security policies. This multi-functional approach consolidates what would otherwise require separate systems, achieving automation without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The metamodel framework acts as an intermediary layer between the virtualization environment and security groups. It translates workload characteristics into appropriate security group assignments, simplifying the interaction between deployment systems and security infrastructure while enabling automated provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3189646B1Method and apparatus for automating security provisioning of workloads
Publication Date: 2023.11.01 CA TECH INC
  • EP3189646B1 patent drawingFigure 1
  • EP3189646B1 patent drawingFigure 2
  • EP3189646B1 patent drawingFigure 3

AI summary

A method of automating security provisioning is provided. The method includes receiving a request to start a virtual application and determining an owner of the virtual application. The method includes determining a workload based on the virtual application, the workload including an application and a virtual machine and assigning the workload to a security container or sub -container, among a plurality of security containers, based on the owner of the virtual application.