Cloud Auditing Device for Virtualized Resource Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtualized network architectures lack effective mechanisms for ensuring compliance with contractual agreements and regulatory requirements, particularly in terms of security and quality of service, as external entities cannot verify the proper deployment and operation of Virtual Network Functions (VNFs) in cloud computing networks.
Innovation Solution
A method and device for auditing virtualized resources in cloud computing networks, which involves memorizing audit rules, correlating event information with these rules, and writing relevant data to a register, ensuring compliance with specified conditions and parameters, including security and performance metrics, while reserving necessary resources and managing data access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtualized network architectures are deployed to reduce costs and increase flexibility, then cost efficiency and adaptability improve, but the ability of external entities to verify compliance with contractual agreements and regulatory requirements deteriorates
Solution Approach 1:
The patent introduces an intermediary auditing system that acts as a mediator between the virtualized network architecture and external entities. This system includes audit rule repositories, event correlation modules, and register writing mechanisms that enable independent verification of compliance without compromising the flexibility of the virtualized architecture. The intermediary translates internal virtualized resource events into auditable records that external regulators and partners can verify.
Solution Approach 2:
The patent implements feedback mechanisms through audit rule correlation and event monitoring. The system continuously monitors events from virtualized resources, correlates them against stored audit rules, and writes compliance status to registers. This creates a closed-loop feedback system where compliance information is continuously generated, stored, and made available for verification, enabling external entities to assess whether service level agreements and regulatory requirements are being met.
2Productivity
If virtualized resources are shared across multiple services and partners, then resource efficiency and cost control improve, but security and quality of service guarantees deteriorate
Solution Approach 1:
The patent applies segmentation by dividing the auditing system into distinct modular components: audit rule repositories, event correlation modules, and register writing mechanisms. Each component handles specific aspects of compliance monitoring independently. This segmentation allows the system to maintain security and quality of service guarantees for different virtualized resources and services while sharing the underlying infrastructure, as each segment can be configured with specific audit rules tailored to its security and performance requirements.
3Productivity
If centralized data center deployment is chosen to pool resources, then cost control and resource sharing improve, but latency and accessibility to customer networks deteriorate
Solution Approach 1:
The auditing system is designed with universality to function effectively across both centralized and distributed deployment scenarios. The audit rule repositories, event correlation modules, and register mechanisms can be deployed at various levels of the network architecture. This multi-functionality allows the same auditing framework to support resource pooling in centralized data centers while also being adaptable to distributed edge deployments closer to customer networks, thereby addressing latency concerns without sacrificing resource sharing benefits.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method (Audit1, Audit 2) for auditing at least one virtualised resource (91, 92, 93) deployed in a cloud computing network, implemented by a device (10, 21, 22, 30) for administrating the at least one said resource, which is able to administrate virtual network functions VNF, the virtual infrastructure NFVI or the OSS/BSS network services, the method comprising: a step of storing a set of rules of the audit, which are associated with the at least one virtualised resource (91, 92, 93); a step of receiving, from the at least one virtualised resource (91, 92, 93), a message containing information about an event happening on said virtualised resource; a step of correlating the information received with the set of stored rules; and if the correlation is positive, a step of sending, to a recording device (41, 42, 43, 44), a message for instructing the writing of at least one piece of data relating to the information received in a data register (51, 52, 53) associated with the at least one virtualised resource (91, 92, 93).