Cloud Governance Session Policies for Dynamic Datacenter Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security restrictions across a large number of dynamic datacenters on cloud platforms is challenging due to the need for centralized governance and seamless security control, especially in multi-tenant systems where datacenters execute different services and network boundaries change frequently.

Innovation Solution

A multi-tenant system uses declarative specifications to configure datacenters on cloud platforms, enforcing session policies and access controls based on network information, allowing for centralized governance and security management by generating cloud platform-specific datacenter representations and managing network restrictions dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized governance and security control are implemented across multiple datacenters, then system security and compliance are improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improvesystem securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a governance system as an intermediary layer between users and datacenters. This system automatically generates access policies based on user roles, datacenter types, and network boundaries, eliminating the need for manual security configuration at each datacenter while maintaining centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security parameters such as access policies, network boundaries, and session restrictions based on contextual information. Access policies are generated by evaluating parameters like user roles, datacenter classifications, and network configurations, allowing adaptive security without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If access policies are manually configured for each datacenter, then security control precision is improved, but loss of time and operational efficiency worsen

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-defining access control frameworks, role-based permission sets, and policy templates before datacenters are accessed. When a datacenter is created or accessed, the system automatically retrieves and applies the appropriate pre-configured policies, eliminating manual configuration time while maintaining precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The governance system provides self-service by automatically generating access policies based on the datacenter's characteristics, user roles, and network boundaries. The system evaluates contextual parameters and autonomously creates appropriate access control measures without requiring manual policy configuration for each datacenter.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If network boundaries and datacenter configurations change dynamically, then adaptability is improved, but security control stability worsens

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsecurity control stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system implements feedback mechanisms that continuously monitor datacenter configurations, network boundaries, and access requests. When changes occur, the system receives feedback about the new state and automatically updates access policies to reflect current configurations, maintaining security stability despite dynamic changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system is designed to be dynamic rather than static. Policies are automatically generated and updated based on real-time evaluation of datacenter types, network boundaries, and user roles, allowing the system to adapt to changing configurations while maintaining consistent security control through automated policy generation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12160451B2Governance and security control for services executing on cloud platforms
Publication Date: 2024.12.03 SALESFORCE INC
  • US12160451B2 patent drawing
  • US12160451B2 patent drawing
  • US12160451B2 patent drawing

AI summary

A cloud infrastructure performs governance and security control for datacenters on a cloud platform. The system specifies one or more session policies for the plurality of datacenters. A session policy associated with a datacenter specifies a set of access conditions for accessing the entities of the datacenter, and may be generated based at least on the network information in the declarative specification for the datacenter, and network artifacts from provisioning the network resources for the datacenter. Responsive to receiving a request to access an entity of a datacenter from a user, the system obtains credentials for the user and attaches the session policies. Responsive to determining that the credentials are used to access the datacenter from a set of access conditions that match the set of access conditions in the attached session policy, the cloud platform grants access.