Cloud Gateway Abstraction Layer for Multi-Provider Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in utilizing cloud infrastructure due to security, control, and manageability issues, preventing them from maximizing their use of cloud computing resources such as virtual server instances, storage, and Internet bandwidth, and they struggle to identify and deploy appropriate cloud resources that align with their technical, operational, and business needs.

Innovation Solution

A cloud computing abstraction layer system that provides a unified interface for accessing and managing disparate public or private cloud resources, enabling self-service access, automated services, rapid provisioning, governance control, and secure access to cloud computing resources, allowing for the planning, building, and deployment of cloud services across various cloud providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If businesses use cloud infrastructure from multiple providers, then resource availability and scalability improve, but security control and manageability deteriorate

Engineering Contradiction:
Improvecloud resource accessVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud gateway as an intermediary component that sits between the enterprise network and multiple cloud providers. This gateway consolidates security policies, authentication mechanisms, and resource management functions into a single centralized point, thereby maintaining security control while enabling access to diverse cloud resources from multiple providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud gateway is designed with multi-functional capabilities including authentication, authorization, encryption, compression, and protocol translation. This universal design allows a single system to handle multiple cloud providers and various cloud services (IaaS, PaaS, SaaS) while maintaining consistent security and management policies across all connections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If cloud services are deployed rapidly, then time to market improves, but security policy enforcement and compliance deteriorate

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring security policies, authentication rules, and compliance requirements in the cloud gateway before cloud services are deployed. This allows security enforcement to be automatically applied from the outset, enabling rapid deployment without compromising compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud gateway implements continuous feedback mechanisms that monitor deployed cloud services for security policy violations and compliance issues. This real-time monitoring and feedback loop ensures that even as services are rapidly deployed and scaled, security policies are consistently enforced and compliance is maintained through automated adjustments and alerts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9069599B2System and method for a cloud computing abstraction layer with security zone facilities
Publication Date: 2015.06.30 VL COLLECTIVE IP LLC
  • US9069599B2 patent drawing
  • US9069599B2 patent drawing
  • US9069599B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for a virtualization environment adapted for development and deployment of at least one software workload, the virtualization environment having a metamodel framework that allows the association of a policy to the software workload upon development of the workload that is applied upon deployment of the software workload. This allows a developer to define a security zone and to apply at least one type of security policy with respect to the security zone including the type of security zone policy in the metamodel framework such that the type of security zone policy can be associated with the software workload upon development of the software workload, and if the type of security zone policy is associated with the software workload, automatically applying the security policy to the software workload when the software workload is deployed within the security zone.