Cloud Security Management via Trusted Service Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in managing security due to the variability of security environments across different clouds or sub-clouds, leading to difficulties in ensuring isolation and compliance with diverse regulatory requirements, which complicates the implementation of secure virtual and hybrid environments.
Innovation Solution
A method is introduced to manage security in cloud computing environments by establishing a trusted relationship between security management service points, obtaining general security requirements, and defining security policies for each cloud entity based on its capabilities and requirements, using a priority-driven algorithm to balance conflicting needs such as service quality and security, and dynamically adapting policies in response to changes or incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud computing dynamically shares and distributes computing work among pooled computers, then resource utilization efficiency is improved, but security control difficulty increases
Solution Approach 1:
The patent segments security management into multiple administrative domains, each with its own security management service point. This allows independent security control in each domain while enabling overall coordination through the trusted relationship establishment mechanism, resolving the contradiction between resource sharing and security control complexity.
Solution Approach 2:
The patent introduces security management service points as intermediary entities that coordinate security policies across different administrative domains. These intermediaries enable centralized security orchestration without direct control of individual pooled computers, maintaining security control efficiency while allowing resource sharing.
2Adaptability or versatility
If virtualized software applications are used to improve flexibility and portability, then ease of deployment is improved, but security isolation capability deteriorates
Solution Approach 1:
The patent applies local quality by allowing each administrative domain to define security policies tailored to its specific requirements and risk profile. Each domain can implement security measures appropriate to its local context while maintaining overall system flexibility and portability through the standardized security management framework.
3Reliability
If cryptographic measures are implemented to comply with privacy protection regulations, then security compliance is improved, but computational cost increases
Solution Approach 1:
The patent enables dynamic adjustment of security policy parameters including cryptographic requirements based on service level agreements and risk assessments. This allows optimization of computational cost by applying cryptographic measures only where and when necessary to meet compliance requirements, rather than uniformly across all cloud operations.
4Adaptability or versatility
If security policies are customized for each administrative domain to meet specific requirements, then security adaptability is improved, but policy management complexity increases
Solution Approach 1:
The patent creates a universal security management framework where security management service points can handle multiple administrative domains with different requirements through a common trusted relationship establishment process. This multi-functional approach allows customized security policies for each domain while using a standardized management mechanism, reducing overall policy management complexity.
Data Source
AI summary
Cloud service security management in cloud computer environment uses a first computer cloud entity with first security capabilities and under security management coordinated by a first security management service point in compliance with predefined first security requirements. Security management of a second computer cloud entity is coordinated by a second security management service point in compliance with predefined second security requirements. In the managing of the security of the cloud service in the cloud computer environment: a trusted relationship is established between the first and second security management service points, general security requirements for the cloud service are obtained; and a first security policy is defined for the first security management service point, based on the general security requirements for the cloud service, the first security capabilities and the first security requirements, for the running of the cloud service by the first computer cloud entity.


