Policy Management Engine for Cloud VM Image Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IaaS cloud networks lack adequate access control, allowing arbitrary virtual machine images to be launched with access to sensitive data, increasing the risk of data breaches and lack of policy-based controls to manage user identities, image attributes, and data sensitivity.

Innovation Solution

A policy management engine is introduced to enforce compliance by intercepting virtual machine image access requests, assessing user identities, image attributes, and data sensitivity, and determining whether the requests conform to defined policies, allowing or blocking the requests accordingly, and triggering management approval workflows when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to launch arbitrary virtual machine images with access to cloud storage resources, then ease of operation is improved, but security and data protection deteriorate

Engineering Contradiction:
Improveease of launching virtual machine imagesVSAvoiddata breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A policy management engine is introduced as an intermediary component between users and the cloud management platform. This engine evaluates launch requests against defined policies, assessing user identities, image attributes, and data sensitivity before allowing image launches. The intermediary enforces access control without preventing legitimate operations, thus maintaining ease of operation while mitigating data breach risks through policy-based filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If cloud vendors provide limited access control support, then device complexity is reduced, but reliability of data protection deteriorates

Engineering Contradiction:
Improveaccess control mechanism complexityVSAvoiddata protection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The access control functionality is segmented into a separate, modular policy management engine that operates independently from the core cloud management platform. This segmentation allows the platform to maintain simplicity while the dedicated policy engine provides robust, specialized data protection capabilities. The policy engine evaluates requests against defined policies, ensuring reliable data protection without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If policies are enforced over user identities, image attributes, and data sensitivity, then data protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata riskVSAvoidoperational simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Policies are defined and configured in advance before any virtual machine image launches occur. The policy management engine uses these pre-defined policies to automatically evaluate launch requests, user identities, image attributes, and data sensitivity classifications. This preliminary configuration approach enables automated, consistent enforcement of data protection measures without requiring users to manually assess risks or configure complex security settings during operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9448826B2Enforcing policy-based compliance of virtual machine image configurations
Publication Date: 2016.09.20 CA TECH INC
  • US9448826B2 patent drawing
  • US9448826B2 patent drawing
  • US9448826B2 patent drawing

AI summary

Techniques are disclosed for data risk management in accessing an Infrastructure as a Service (IaaS) cloud network. More specifically, embodiments of the invention evaluate virtual machine images launched in cloud-based environments for compliance with a policy. After intercepting a virtual machine image launch request, an intermediary policy management engine determines whether the request conforms to a policy defined by a policy manager, e.g., an enterprise's information security officer. The policy may be based on user identities, virtual machine image attributes, data classifications, or other criteria. Upon determining whether the request conforms to policy, the policy management engine allows the request, blocks the request, or triggers a management approval workflow.