Cloud Data Access via Virtual Machine Launcher and Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud infrastructure arrangements pose security concerns for enterprises as they require private data to be copied into persistent storage of public clouds for application execution, compromising data security.

Innovation Solution

Implementing a system where applications execute in a public cloud without requiring private data to be stored persistently, using a virtual machine instance with an application launcher and data proxy that communicates with an enterprise storage system for non-persistent data transfer, ensuring data remains secure within the enterprise storage system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If private data is copied into persistent storage of public cloud for application execution, then application execution capability is improved, but data security deteriorates

Engineering Contradiction:
Improveapplication execution capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts private data from the cloud execution environment and keeps it exclusively in enterprise-controlled storage. Only application code and non-sensitive data are deployed to the public cloud, while sensitive data remains in the enterprise data center and is accessed through secure data access protocols during application execution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a data access layer as an intermediary between the cloud-based application and enterprise data. This layer includes data access policies, authentication mechanisms, and secure data transfer protocols that enable applications to access private data without compromising security. The intermediary controls and monitors all data access operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private data is stored persistently in public cloud, then data accessibility for cloud applications is improved, but security control by enterprise deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data into different categories based on sensitivity and access requirements. Sensitive private data is stored separately in enterprise-controlled storage, while non-sensitive data can be cached in the cloud. This segmentation allows differential access control policies to be applied, maintaining security for sensitive data while enabling easy access for non-sensitive data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication and authorization checks before allowing any data access operations. Data access policies are pre-configured and enforced before data transfer occurs, ensuring that only authenticated applications with proper permissions can access private data, thereby maintaining security control while enabling accessibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10609143B1Secure data access in cloud computing environments
Publication Date: 2020.03.31 EMC IP HLDG CO LLC
  • US10609143B1 patent drawing
  • US10609143B1 patent drawing
  • US10609143B1 patent drawing

AI summary

An apparatus in one embodiment comprises cloud infrastructure having at least a first cloud. The apparatus further comprises a storage system separate from the first cloud and providing persistent storage for an application and associated data. The first cloud comprises a virtual machine image having installed therein an application launcher for the application of the storage system. Responsive to a request to execute the application, the first cloud configures a virtual machine instance based on the virtual machine image to execute the application launcher. In conjunction with the execution of the application launcher, the application is loaded from the storage system into the virtual machine instance for execution. In conjunction with the execution of the application, a data proxy associated with the application communicates with the storage system to transfer portions of the data required for execution of the application into non-persistent storage of the virtual machine instance.