Model-Based Security Management for Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment and securing of virtual machines are separate tasks that often lead to resource inefficiencies and security risks due to manual coordination and potential disconnects between management and security, resulting in errors and inconsistencies.

Innovation Solution

A model-based systems management architecture that integrates a security component to define security requirements for services using virtual machines, applying these requirements throughout the lifecycle of services and virtual machines, including deployment, expansion, monitoring, and reporting, with features like virtual machine to physical machine mapping, host hardening, and firewall/IDS/IPS configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deployment and securing of virtual machines are performed as separate manual tasks, then flexibility in deployment is maintained, but security risks increase and resource efficiency decreases

Engineering Contradiction:
Improvesecurity complianceVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the deployment task and the securing task into a single integrated automated process. The system automatically applies security configurations, firewall rules, and compliance policies during the virtual machine deployment process itself, eliminating the need for separate manual coordination between deployment and security teams. This merging resolves the contradiction by maintaining deployment flexibility while improving security compliance through automation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs security configurations as preliminary actions during the deployment process itself, rather than as subsequent separate steps. Security policies, firewall rules, and compliance settings are applied automatically at the moment of virtual machine creation, ensuring security is built-in from the start. This preliminary action approach improves security compliance while reducing the coordination complexity that would arise from subsequent separate security tasks.

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If manual coordination between management and security is used, then adaptability to different scenarios is maintained, but errors and inconsistencies increase

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidoperational simplicity
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The system implements self-service automation where the deployment process automatically retrieves and applies the appropriate security configurations, firewall rules, and compliance policies without requiring manual intervention. The system serves itself by automatically coordinating between deployment requirements and security requirements, ensuring consistent and accurate security configurations while simplifying the operational process for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms that automatically verify whether security configurations have been correctly applied during deployment. The automated process monitors and confirms that security policies are properly implemented, providing feedback loops that ensure configuration accuracy. This feedback approach improves manufacturing precision in security configurations while maintaining ease of operation through automation.

Inventive Principle:
Principle #23Feedback

3Productivity

If separate tasks are used for deployment and securing, then task specialization is maintained, but resource efficiency decreases

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidcoordination time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges the deployment task and securing task into a single automated workflow that executes both functions simultaneously. By combining these tasks, the system eliminates the time loss associated with manual coordination between separate teams while maintaining the productivity benefits of specialized functions. The integrated automation resolves the contradiction by reducing coordination time without sacrificing deployment efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system ensures continuous useful action by executing security configurations as an uninterrupted part of the deployment process itself. Rather than pausing deployment for separate security tasks or requiring manual handoffs, the automated system continuously performs both deployment and securing operations in a seamless workflow. This continuity improves productivity while eliminating the time loss from coordination between separate tasks.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8726334B2Model based systems management in virtualized and non-virtualized environments
Publication Date: 2014.05.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8726334B2 patent drawing
  • US8726334B2 patent drawing
  • US8726334B2 patent drawing

AI summary

Architecture that provides model-based systems management in virtualized and non-virtualized environments. A security component provides security models which define security requirements for services. A management component applies one or more of the security models during the lifecycle of virtual machines and services. The lifecycle can include initial deployment, expansion, moving servers, monitoring, and reporting. The architecture creates a formal description model of how a virtual machine or a service (composition of multiple virtual machines) is secured. The security requirements information can also be fed back to the general management system which uses this information in its own activities such as to guide the placement of workloads on servers can be security related.