Cloud Auditing Device for Virtualized Resource Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualized network architectures lack effective mechanisms for ensuring compliance with contractual agreements and regulatory requirements, particularly in terms of security and quality of service, as external entities cannot verify the proper deployment and operation of Virtual Network Functions (VNFs) in cloud computing networks.

Innovation Solution

A method and device for auditing virtualized resources in cloud computing networks, which involves memorizing audit rules, correlating event information with these rules, and writing relevant data to a register, ensuring compliance with specified conditions and parameters, including security and performance metrics, while reserving necessary resources and managing data access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualized network architectures are deployed to reduce costs and increase flexibility, then cost efficiency and adaptability improve, but the ability of external entities to verify compliance with contractual agreements and regulatory requirements deteriorates

Engineering Contradiction:
ImproveflexibilityVSAvoidcompliance verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary auditing system that acts as a mediator between the virtualized network architecture and external entities. This system includes audit rule repositories, event correlation modules, and register writing mechanisms that enable independent verification of compliance without compromising the flexibility of the virtualized architecture. The intermediary translates internal virtualized resource events into auditable records that external regulators and partners can verify.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms through audit rule correlation and event monitoring. The system continuously monitors events from virtualized resources, correlates them against stored audit rules, and writes compliance status to registers. This creates a closed-loop feedback system where compliance information is continuously generated, stored, and made available for verification, enabling external entities to assess whether service level agreements and regulatory requirements are being met.

Inventive Principle:
Principle #23Feedback

2Productivity

If virtualized resources are shared across multiple services and partners, then resource efficiency and cost control improve, but security and quality of service guarantees deteriorate

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity and quality of service
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the auditing system into distinct modular components: audit rule repositories, event correlation modules, and register writing mechanisms. Each component handles specific aspects of compliance monitoring independently. This segmentation allows the system to maintain security and quality of service guarantees for different virtualized resources and services while sharing the underlying infrastructure, as each segment can be configured with specific audit rules tailored to its security and performance requirements.

Inventive Principle:
Principle #1Segmentation

3Productivity

If centralized data center deployment is chosen to pool resources, then cost control and resource sharing improve, but latency and accessibility to customer networks deteriorate

Engineering Contradiction:
Improveresource sharingVSAvoidlatency
Core Design Contradiction:
ProductivityVSSpeed

Solution Approach 1:

The auditing system is designed with universality to function effectively across both centralized and distributed deployment scenarios. The audit rule repositories, event correlation modules, and register mechanisms can be deployed at various levels of the network architecture. This multi-functionality allows the same auditing framework to support resource pooling in centralized data centers while also being adaptable to distributed edge deployments closer to customer networks, thereby addressing latency concerns without sacrificing resource sharing benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3519958B1Method for auditing a virtualised resource deployed in a cloud computing network
Publication Date: 2023.11.08 ORANGE SA
  • EP3519958B1 patent drawingFigure 1
  • EP3519958B1 patent drawingFigure 2
  • EP3519958B1 patent drawingFigure 3

AI summary

The invention relates to a method (Audit1, Audit 2) for auditing at least one virtualised resource (91, 92, 93) deployed in a cloud computing network, implemented by a device (10, 21, 22, 30) for administrating the at least one said resource, which is able to administrate virtual network functions VNF, the virtual infrastructure NFVI or the OSS/BSS network services, the method comprising: a step of storing a set of rules of the audit, which are associated with the at least one virtualised resource (91, 92, 93); a step of receiving, from the at least one virtualised resource (91, 92, 93), a message containing information about an event happening on said virtualised resource; a step of correlating the information received with the set of stored rules; and if the correlation is positive, a step of sending, to a recording device (41, 42, 43, 44), a message for instructing the writing of at least one piece of data relating to the information received in a data register (51, 52, 53) associated with the at least one virtualised resource (91, 92, 93).