Cloud Isolation Zones for VSAN and VLAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments lack effective methods for isolating services between competing entities, leading to potential data path interference and security concerns.

Innovation Solution

The creation of isolation zones using user-input values for VSANs, virtualization management VLANs, file storage VLANs, and identity pools, allowing for the separation of data paths between different services within a cloud computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If services are hosted in the same cloud infrastructure without isolation zones, then resource utilization and scalability are improved, but security and data path isolation deteriorate

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the cloud infrastructure into distinct isolation zones, each containing specific services. This is achieved through creating separate network segments, storage zones, and compute environments that are logically or physically separated. The segmentation allows multiple services to coexist in the same infrastructure while maintaining security boundaries, thus resolving the contradiction between scalability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different security and isolation characteristics in different parts of the infrastructure. Each isolation zone can have customized security policies, network configurations, and access controls tailored to specific service requirements. This enables high-security zones for sensitive services while maintaining open, scalable zones for less critical services, simultaneously achieving both security and scalability.

Inventive Principle:
Principle #3Local quality

2Reliability

If isolation zones are created for competing entities, then security and data path isolation are improved, but system complexity and configuration overhead increase

Engineering Contradiction:
Improvedata path isolationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized isolation zone framework that can be applied across multiple services and entities. The system provides universal templates and policies for creating isolation zones that work consistently across different services, reducing configuration complexity. The multi-functional isolation zones can serve multiple purposes (security, resource management, networking) simultaneously, simplifying overall system management while maintaining strong data path isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service through automated isolation zone creation and management capabilities. The system can automatically provision isolation zones based on service requirements, configure appropriate security policies, and manage resource allocation without manual intervention. This automation reduces configuration overhead and complexity while maintaining robust data path isolation, allowing the system to self-manage the complexity of multiple isolated zones.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9692824B1Methods and apparatus for providing isolation zones in a cloud computing environment
Publication Date: 2017.06.27 EMC IP HLDG CO LLC
  • US9692824B1 patent drawing
  • US9692824B1 patent drawing
  • US9692824B1 patent drawing

AI summary

Methods and apparatus to create with user input a first isolation zone in a block in a cloud computing environment, the block comprising first and second VSANs, a virtualization management VLAN, a file storage VLAN, and identity pools. The isolation zone can be applied to one or more services. The user can achieve a desired isolation between block components, such as VSANs and/or VLANs, in services.