Private Virtual Machine Provisioning in Public Cloud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in securely provisioning and managing private virtual machines on public clouds, as public-facing servers may be reluctant to host applications that require access to sensitive data, necessitating a solution to ensure secure and controlled access.
Innovation Solution
A computer system receives authentication information from entities to establish private virtual networks on public clouds, configuring virtual machines to host remote applications with access to the entity's private domain, allowing for secure provisioning and management of these machines without requiring user input for management actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If public-facing cloud servers host applications requiring access to sensitive data, then cloud computing accessibility and scalability are improved, but security and control over sensitive data are worsened
Solution Approach 1:
A virtual network acts as an intermediary layer between public cloud servers and private domain data. This virtual network enables applications hosted on public cloud servers to securely access sensitive data in private domains without exposing the data directly to the public internet, thus maintaining both accessibility and security.
Solution Approach 2:
The system segments the network into distinct components: public cloud infrastructure, virtual network layer, and private domain. This segmentation allows public-facing applications to remain accessible while sensitive data remains isolated in the private domain, accessed only through controlled virtual network connections.
2Reliability
If manual authentication and provisioning processes are used for private virtual machines, then security control is improved, but provisioning time and operational complexity are worsened
Solution Approach 1:
Authentication information is collected and validated in advance during the initial setup phase. Once authenticated, the system pre-configures virtual networks and establishes secure connections to private domains before applications are deployed, eliminating the need for manual authentication during each provisioning event.
Solution Approach 2:
The system implements automated authentication and provisioning processes where the computer system automatically validates credentials, creates virtual networks, and configures connections without requiring ongoing manual intervention. This self-service approach maintains security through pre-established authentication while dramatically reducing provisioning time.
3Productivity
If automated management actions are implemented for virtual machines, then operational efficiency is improved, but security risks from unauthorized actions are worsened
Solution Approach 1:
The system implements feedback mechanisms where automated management actions are monitored and validated against established security policies. The computer system receives authentication information and uses it to verify that automated actions are authorized, providing continuous feedback control to prevent unauthorized operations while maintaining operational efficiency.
Data Source
AI summary
Embodiments are directed to provisioning private virtual machines in a public cloud and to managing private virtual machines hosted on a public cloud. In one scenario, a computer system receives authentication information for a private domain from an entity. The entity indicates that their private virtual machines are to be provisioned on a public cloud, where the entity's private domain is accessible using the authentication information. The computer system establishes a virtual network on the public cloud which is configured to host the entity's private virtual machines, where each virtual machine hosts remote applications. The computer system establishes an authenticated connection from the virtual network to the entity's private domain using the received authentication information and provides the entity's private virtual machines on the public cloud. The remote applications provided by the private virtual machines then have access to data stored within the entity's private domain using the authenticated connection.


