Cloud Governance Session Policies for Dynamic Datacenter Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing security restrictions across a large number of dynamic datacenters on cloud platforms is challenging due to the need for centralized governance and seamless security control, especially in multi-tenant systems where datacenters execute different services and network boundaries change frequently.
Innovation Solution
A multi-tenant system uses declarative specifications to configure datacenters on cloud platforms, enforcing session policies and access controls based on network information, allowing for centralized governance and security management by generating cloud platform-specific datacenter representations and managing network restrictions dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized governance and security control are implemented across multiple datacenters, then system security and compliance are improved, but device complexity and management difficulty increase
Solution Approach 1:
The patent introduces a governance system as an intermediary layer between users and datacenters. This system automatically generates access policies based on user roles, datacenter types, and network boundaries, eliminating the need for manual security configuration at each datacenter while maintaining centralized control.
Solution Approach 2:
The system dynamically adjusts security parameters such as access policies, network boundaries, and session restrictions based on contextual information. Access policies are generated by evaluating parameters like user roles, datacenter classifications, and network configurations, allowing adaptive security without manual intervention.
2Measurement precision
If access policies are manually configured for each datacenter, then security control precision is improved, but loss of time and operational efficiency worsen
Solution Approach 1:
The system performs preliminary action by pre-defining access control frameworks, role-based permission sets, and policy templates before datacenters are accessed. When a datacenter is created or accessed, the system automatically retrieves and applies the appropriate pre-configured policies, eliminating manual configuration time while maintaining precision.
Solution Approach 2:
The governance system provides self-service by automatically generating access policies based on the datacenter's characteristics, user roles, and network boundaries. The system evaluates contextual parameters and autonomously creates appropriate access control measures without requiring manual policy configuration for each datacenter.
3Adaptability or versatility
If network boundaries and datacenter configurations change dynamically, then adaptability is improved, but security control stability worsens
Solution Approach 1:
The system implements feedback mechanisms that continuously monitor datacenter configurations, network boundaries, and access requests. When changes occur, the system receives feedback about the new state and automatically updates access policies to reflect current configurations, maintaining security stability despite dynamic changes.
Solution Approach 2:
The access control system is designed to be dynamic rather than static. Policies are automatically generated and updated based on real-time evaluation of datacenter types, network boundaries, and user roles, allowing the system to adapt to changing configurations while maintaining consistent security control through automated policy generation.
Data Source
AI summary
A cloud infrastructure performs governance and security control for datacenters on a cloud platform. The system specifies one or more session policies for the plurality of datacenters. A session policy associated with a datacenter specifies a set of access conditions for accessing the entities of the datacenter, and may be generated based at least on the network information in the declarative specification for the datacenter, and network artifacts from provisioning the network resources for the datacenter. Responsive to receiving a request to access an entity of a datacenter from a user, the system obtains credentials for the user and attaches the session policies. Responsive to determining that the credentials are used to access the datacenter from a set of access conditions that match the set of access conditions in the attached session policy, the cloud platform grants access.


