Cloud Data Access via Virtual Machine Launcher and Proxy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud infrastructure arrangements pose security concerns for enterprises as they require private data to be copied into persistent storage of public clouds for application execution, compromising data security.
Innovation Solution
Implementing a system where applications execute in a public cloud without requiring private data to be stored persistently, using a virtual machine instance with an application launcher and data proxy that communicates with an enterprise storage system for non-persistent data transfer, ensuring data remains secure within the enterprise storage system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If private data is copied into persistent storage of public cloud for application execution, then application execution capability is improved, but data security deteriorates
Solution Approach 1:
The patent extracts private data from the cloud execution environment and keeps it exclusively in enterprise-controlled storage. Only application code and non-sensitive data are deployed to the public cloud, while sensitive data remains in the enterprise data center and is accessed through secure data access protocols during application execution.
Solution Approach 2:
The patent introduces a data access layer as an intermediary between the cloud-based application and enterprise data. This layer includes data access policies, authentication mechanisms, and secure data transfer protocols that enable applications to access private data without compromising security. The intermediary controls and monitors all data access operations.
2Ease of operation
If private data is stored persistently in public cloud, then data accessibility for cloud applications is improved, but security control by enterprise deteriorates
Solution Approach 1:
The patent segments data into different categories based on sensitivity and access requirements. Sensitive private data is stored separately in enterprise-controlled storage, while non-sensitive data can be cached in the cloud. This segmentation allows differential access control policies to be applied, maintaining security for sensitive data while enabling easy access for non-sensitive data.
Solution Approach 2:
The patent implements preliminary authentication and authorization checks before allowing any data access operations. Data access policies are pre-configured and enforced before data transfer occurs, ensuring that only authenticated applications with proper permissions can access private data, thereby maintaining security control while enabling accessibility.
Data Source
AI summary
An apparatus in one embodiment comprises cloud infrastructure having at least a first cloud. The apparatus further comprises a storage system separate from the first cloud and providing persistent storage for an application and associated data. The first cloud comprises a virtual machine image having installed therein an application launcher for the application of the storage system. Responsive to a request to execute the application, the first cloud configures a virtual machine instance based on the virtual machine image to execute the application launcher. In conjunction with the execution of the application launcher, the application is loaded from the storage system into the virtual machine instance for execution. In conjunction with the execution of the application, a data proxy associated with the application communicates with the storage system to transfer portions of the data required for execution of the application into non-persistent storage of the virtual machine instance.


