Model-Based Security for Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security techniques in cloud computing environments fail to adequately secure services based on their resource allocations, leading to potential compromises within the network environment as cloud services may inadvertently access or interfere with each other's resources.

Innovation Solution

A model-based security scheme is applied to cloud services, derived from an application service model that includes resource allocation plans and descriptions, enforcing limitations and restrictions through various security layers such as network filters, virtual machine security, and process security to isolate and protect applications from unauthorized access and resource misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security techniques are used in cloud computing environments, then security measures are implemented, but services can still compromise each other's security and access resources unauthorizedly

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the cloud computing environment into isolated service instances, each with its own security context. The security scheme segments access rights and resource allocation at the service level, ensuring that one service cannot access another service's resources without explicit permission. This is implemented through the service model's resource allocation plan that defines precise access boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by tailoring security measures to each individual service based on its specific resource allocation and operational requirements. Each service receives customized security controls aligned with its allocated CPU, memory, storage, and network resources, rather than applying uniform security policies. This allows security to be optimized for each service's actual needs and potential threats.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If security restrictions are imposed on cloud services, then unauthorized access is prevented, but service functionality and resource utilization may be limited

Engineering Contradiction:
Improveunauthorized accessVSAvoidservice functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by establishing security restrictions and resource allocation boundaries before the service executes. The service model is configured in advance with defined resource allocation plans that specify CPU shares, memory limits, storage quotas, and network access rights. These constraints are pre-imposed through the security scheme, allowing services to operate within their authorized parameters without requiring runtime security decisions that could limit functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that monitor service behavior against the defined security model and resource allocation plan. When services attempt to access resources outside their allocated boundaries or violate security policies, the system detects these actions and enforces restrictions. This feedback loop ensures services maintain their intended functionality while preventing unauthorized access to other services or infrastructure.

Inventive Principle:
Principle #23Feedback

3Reliability

If model-based security schemes are implemented, then resource constraints are enforced, but system complexity increases

Engineering Contradiction:
Improveresource constraintsVSAvoidsecurity scheme complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a unified security scheme that handles multiple security functions through a single integrated framework. The service model-based approach simultaneously manages resource allocation, access control, security policy enforcement, and audit logging through one coherent system. This multi-functional design reduces overall system complexity compared to having separate security mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by creating a virtualized service model that represents the security context and resource allocation for each service. Instead of implementing complex physical security measures for every resource, the system creates abstract representations (copies) of service boundaries and resource limits that can be enforced through software. This virtual copying approach simplifies the enforcement of resource constraints while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8621553B2Model based security for cloud services
Publication Date: 2013.12.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8621553B2 patent drawing
  • US8621553B2 patent drawing
  • US8621553B2 patent drawing

AI summary

Applications, such as cloud services, may be deployed within a network environment (e.g., a cloud computing environment). Unfortunately, when the applications are instantiated within the network environment, they have the ability to compromise the security of other applications and/or the infrastructure of the network environment. Accordingly, as provided herein, a security scheme may be applied to a network environment within which an application is to be instantiated. The security scheme may comprise one or more security layers (e.g., virtual machine level security, application level security, operating system level security, etc.) derived from an application service model describing the application and/or resources allocated to the application.