Hybrid Cloud Security Model Extension via Unified Access Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hybrid cloud environments face challenges in managing separate and distinct security models for public and private clouds, leading to increased costs, inconsistent security models, and the need for significant time and resource commitments.

Innovation Solution

The method and system extend the security model employed within the private cloud to encompass access to public cloud resources by defining public cloud access permissions in accordance with the private cloud security model, and using an access module to process access requests uniformly across both cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate and distinct security models are implemented for public and private clouds, then security control can be customized for each cloud environment, but device complexity and management overhead increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidsecurity model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security models of public and private clouds into a unified hybrid cloud security model. The access control module consolidates permission definitions and access requests from both cloud environments, applying consistent security policies across the entire hybrid cloud infrastructure rather than maintaining separate security models.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access control module is designed to handle multiple functions: it manages access permissions for both public and private cloud resources, processes access requests from either cloud environment, and enforces security policies uniformly across the hybrid cloud system, replacing the need for multiple specialized security modules.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate security models are developed for public and private clouds, then each cloud can have optimized security policies, but the time and resources required for development and maintenance increase considerably

Engineering Contradiction:
Improvesecurity policy optimizationVSAvoidsecurity model development time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the security policy management processes for public and private clouds into a single unified system. The access control module maintains a consolidated set of security policies that apply to both cloud environments, eliminating the need to develop and maintain separate policy sets for each cloud type.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If separate access interfaces are provided for public and private clouds, then access control can be tailored to each cloud's specific requirements, but ease of operation deteriorates due to multiple interfaces

Engineering Contradiction:
Improveaccess interface usabilityVSAvoidcloud-specific access control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The access control module serves as a universal interface that handles access requests for both public and private cloud resources through a single consistent mechanism. It maintains the ability to apply cloud-specific security policies while presenting a unified access interface to users, eliminating the need for separate access procedures for different cloud environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12204669B2Extending private cloud security model to public cloud
Publication Date: 2025.01.21 DELL PROD LP
  • US12204669B2 patent drawing
  • US12204669B2 patent drawing

AI summary

Methods and systems disclosed herein extend an entity's private cloud security model to the entity's public cloud. Public cloud access permissions are defined, in accordance with a security model implemented in the entity's private cloud, for one or more of the entity's public cloud resources. The public cloud permissions are pushed or otherwise provided to an access module within the private cloud. Upon receiving a request to access a public cloud resource, the private cloud access module is invoked to grant or deny the access request in accordance with the public cloud access permissions. Similarly, upon receiving a request to access a private cloud resource, the private cloud access module is invoked to process the access request in accordance with private cloud access permissions, thereby beneficially enabling users to interact with a single access interface regardless of whether the resource reside within the entity's cloud platform.