Cloud Tagging Orchestrator for Multi-Cloud Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud customers face difficulties in maintaining and standardizing tags across multiple cloud providers in a hybrid public/private multi-cloud environment, leading to inconsistencies that complicate the implementation and enforcement of security policies.

Innovation Solution

A centralized cloud-tagging orchestrator service, running on a security manager, receives information from multiple cloud providers and assigns unified tags to cloud resources based on a pre-defined global tagging policy, facilitating intent-based security policies and ensuring consistent tagging across different cloud platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud providers use their own tagging conventions for cloud resources, then each provider can manage its resources independently and efficiently, but inconsistencies arise across multi-cloud environments that complicate security policy implementation

Engineering Contradiction:
Improvecloud provider independenceVSAvoidsecurity policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud tagging orchestrator service as an intermediary layer between cloud providers and security policy management systems. This orchestrator receives resource information from multiple cloud providers, applies a global tagging policy to generate unified tags, and assigns these tags to cloud resources. This intermediary mechanism allows cloud providers to maintain their independent tagging conventions while presenting a unified tag structure to security policies, thereby resolving the contradiction between provider independence and policy management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the tagging system into two distinct layers: the cloud provider's native tagging layer and the unified global tagging layer. The cloud tagging orchestrator service operates at the boundary between these layers, translating provider-specific tags into unified tags according to the global tagging policy. This segmentation allows each cloud provider to maintain its own tagging conventions independently while the unified layer ensures consistency across the multi-cloud environment for security policy enforcement.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If manual tagging of cloud resources is performed across multiple cloud providers, then tagging can be customized for each resource, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvetagging flexibilityVSAvoidtagging time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining a global tagging policy that specifies the tagging structure, hierarchy, and conventions to be applied across all cloud resources. This global tagging policy is established in advance and stored in the cloud tagging orchestrator service. When cloud resources are created or updated, the orchestrator automatically retrieves the pre-defined policy and applies the appropriate unified tags without requiring manual intervention, thereby significantly reducing tagging time while maintaining flexibility through the pre-configured policy options.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud tagging orchestrator service enables self-service tagging by automatically retrieving resource information from cloud providers, applying the global tagging policy, and assigning unified tags without human intervention. The system autonomously manages the entire tagging process, including receiving resource data, determining appropriate tags based on the global policy, and updating resource tags through cloud provider APIs. This automation eliminates manual tagging operations while preserving tagging flexibility through the configurable global policy.

Inventive Principle:
Principle #25Self-service

3Reliability

If unified tagging is implemented across multiple cloud providers, then security policy consistency is improved, but integration complexity and orchestration overhead increase

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidorchestration system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud tagging orchestrator service implements universality by designing a single, multi-functional platform that can manage tagging across multiple cloud providers (AWS, Azure, GCP, etc.) through a unified interface. The service universally applies the global tagging policy to all cloud resources regardless of the underlying provider, and universally communicates with different cloud provider APIs using standardized interaction patterns. This universal approach ensures security policy consistency across all clouds while containing orchestration complexity within a single multi-capable system rather than requiring separate solutions for each provider.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11290527B2Automatic tagging of cloud resources for implementing security policies
Publication Date: 2022.03.29 FORTINET INC
  • US11290527B2 patent drawing
  • US11290527B2 patent drawing
  • US11290527B2 patent drawing

AI summary

Systems and methods for automatically tagging cloud resources that are spread across multiple cloud platforms are provided. According to one embodiment, information regarding each cloud provider of multiple cloud providers associated with a cloud environment used by a private network is received by a cloud-tagging orchestrator service of the private network. For each cloud resource of a plurality of cloud resources hosted by the cloud providers on behalf of the private network: (i) information associated with the cloud resource is retrieved by the cloud-tagging orchestrator service; (ii) a unified tag of multiple unified tags for the cloud resource is identified by the cloud-tagging orchestrator service based on a pre-defined global tagging policy; and (ii) the unified tag is assigned by the cloud-tagging orchestrator service to the cloud resource via an application programming interface (API) of a cloud provider of the multiple cloud providers hosting the resource.