Compound Policy Topology for Cloud Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing systems face challenges in enforcing access control policy rules effectively across virtual machines, particularly in protecting physical boundaries, increasing enforcement on virtualization-supported operating systems, and minimizing the footprint of access control agents.
Innovation Solution
A system comprising a policy life cycle component that maintains a repository of security policies, issuing compound policies for virtual hosts and virtual machines, and a topology manager that assigns these policies to access control agents, creating a security policy topology to enforce access control rules and restrict virtual I/O access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control methods are used in cloud computing systems, then implementation is simpler, but security enforcement across virtual machines is ineffective
Solution Approach 1:
The access control system is segmented into multiple components: a policy life cycle component for policy management, a topology manager for policy distribution, and access control agents deployed on each virtual machine. This segmentation allows effective security enforcement across distributed virtual machines while maintaining manageable complexity through modular design.
Solution Approach 2:
The patent introduces a topology manager as an intermediary component that bridges the policy life cycle component and access control agents. The topology manager maintains a security policy topology that maps relationships between virtual machines and their corresponding agents, enabling effective policy enforcement without requiring direct complex interactions between all system components.
2Reliability
If access control agents are deployed on each virtual machine, then enforcement capability increases, but agent footprint increases
Solution Approach 1:
Access control agents are designed to be self-contained and self-managing components that operate autonomously on each virtual machine. Each agent independently enforces policies assigned to its host virtual machine without requiring additional external management infrastructure, minimizing the footprint while maintaining enforcement capability.
3Manufacturing precision
If compound policies are issued for each virtual machine, then access control precision increases, but policy management complexity increases
Solution Approach 1:
The policy life cycle component provides universal policy management functionality that serves all virtual machines through a common interface and centralized repository. Compound policies are issued from this universal source, ensuring precise access control for each virtual machine while avoiding the complexity of multiple separate policy management systems through the multi-functional capability of the centralized component.
Data Source
AI summary
According to one embodiment, a system comprises one or more processors coupled to a memory and executing logic. A policy life cycle component is configured to maintain a repository of security policies. The repository of security policies comprises policies governing access to a virtual host and to a plurality of virtual machines running on the virtual host. The policy life cycle component is also configured to issue a compound policy for an identified virtual operating system running on the virtual host. The compound policy provides a virtual host policy and access rules for each of the plurality of virtual machines running on the virtual host. A topology manager is configured to receive the compound policy from the policy life cycle component, assign the compound to an access control agent, and maintain a security policy topology. The security policy topology stores associations between access control agents and compound policies.


