Cloud Abstraction Layer for Secure Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in utilizing cloud infrastructure due to security, control, and manageability issues, preventing them from maximizing cloud computing resources such as virtual server instances, storage, and Internet bandwidth, and they struggle to identify and utilize appropriate cloud resources that align with their technical, operational, and business needs.

Innovation Solution

A cloud computing abstraction layer system that provides self-service access to cloud resources, enables automated management and governance, and allows for rapid provisioning and scaling of cloud services, offering a unified interface for disparate public and private cloud resources, and enforcing security and policy compliance through a policy engine and identity management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If businesses directly use cloud infrastructure from providers, then access to computing resources is obtained, but security and control issues prevent maximization of resource utilization

Engineering Contradiction:
Improvecloud resource utilizationVSAvoidsecurity and control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a cloud computing abstraction layer as an intermediary between businesses and cloud infrastructure providers. This abstraction layer includes a self-service portal and policy engine that mediates resource access, enabling businesses to securely manage and utilize cloud resources without directly interfacing with underlying infrastructure, thus resolving the security-control versus utilization contradiction

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments cloud resource management into distinct functional layers: a self-service portal for user interaction, a policy engine for security enforcement, and an abstraction layer for resource coordination. This segmentation allows security policies to be applied at the abstraction layer while maintaining full resource access capabilities, enabling both high utilization and strong security

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If businesses use multiple cloud providers, then resource options increase, but difficulty in identifying and managing appropriate resources increases

Engineering Contradiction:
Improvecloud resource optionsVSAvoidresource management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cloud computing abstraction layer provides a universal interface that works across multiple cloud providers and resource types. The self-service portal presents a unified view of available resources from different providers, and the policy engine applies consistent management rules regardless of the underlying provider, enabling businesses to leverage diverse cloud options without managing the complexity of each individual provider's interface and policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual management of cloud resources is used, then security control is maintained, but time to deploy and scale applications increases

Engineering Contradiction:
Improvesecurity controlVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service automation where the abstraction layer and policy engine automatically manage cloud resource provisioning, scaling, and security enforcement. Businesses can deploy applications rapidly through automated workflows that handle security policies and resource allocation without manual intervention, achieving both fast deployment and maintained security control through automated policy enforcement

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10880189B2System and method for a cloud computing abstraction with self-service portal for publishing resources
Publication Date: 2020.12.29 VL COLLECTIVE IP LLC
  • US10880189B2 patent drawing
  • US10880189B2 patent drawing
  • US10880189B2 patent drawing

AI summary

In embodiments of the present invention, improved capabilities are described for a virtualization environment adapted for development and deployment of at least one software workload, the virtualization environment having a metamodel framework that allows the association of a policy to the software workload upon development of the workload that is applied upon deployment of the software workload.