Secure Application Zones for Cloud Bursting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing, application developers face challenges in evaluating and ensuring the security of their applications during deployment, especially when bursting into new cloud infrastructures with different security capabilities, leading to potential security risks and complexities.

Innovation Solution

A security assurance service is introduced to create and manage secure application zones within cloud infrastructures, which identifies security requirements and capabilities in the new environment, computes the minimal security needs, and configures the necessary topology to ensure secure deployment during cloud bursting operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application developers are empowered with operational capability in virtualized environments, then deployment flexibility improves, but security evaluation capability deteriorates due to lack of security background knowledge

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity evaluation capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security assurance service as an intermediary between application developers and the complex security infrastructure. This service automatically evaluates security requirements, analyzes cloud environment capabilities, and configures secure application zones without requiring developers to have security expertise. The intermediary translates developer intent into security configurations, resolving the contradiction between deployment flexibility and security evaluation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud bursting is implemented to meet peak demand, then productivity improves, but security risk increases due to different security capabilities in target environments

Engineering Contradiction:
Improvepeak demand handling capabilityVSAvoidsecurity consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by having the security assurance service pre-evaluate security requirements of applications and pre-analyze security capabilities of potential cloud burst target environments before actual bursting occurs. This advance preparation ensures that security configurations are ready and compatible, preventing security inconsistencies when applications burst to cloud environments with different security capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts security configuration parameters based on the specific cloud environment being targeted for bursting. The security assurance service analyzes the security capabilities of the target environment and modifies security zone configurations to match and maintain security consistency across different cloud infrastructures, enabling productive cloud bursting while maintaining security reliability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual security configuration is performed by security experts, then security reliability improves, but device complexity increases due to increasingly complex security software deployments

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidsecurity deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the security assurance service to automatically configure secure application zones without requiring manual intervention from security experts. The service autonomously evaluates security requirements, analyzes cloud environment capabilities, computes minimal security environments, and configures security topologies. This automation maintains security reliability while dramatically reducing deployment complexity and making security management accessible to application developers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10244002B2Secure application zones for cloud burst environments
Publication Date: 2019.03.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10244002B2 patent drawing
  • US10244002B2 patent drawing
  • US10244002B2 patent drawing

AI summary

A cloud infrastructure security assurance service is enhanced to facilitate bursting of cloud applications into other cloud infrastructures. The security assurance service provides a mechanism to enable creation and management of secure application zones within a cloud infrastructure. When the security assurance service receives an indication that a workload associated with a cloud application triggers a cloud burst, the service is extended into a new cloud infrastructure. Once the security assurance service is instantiated in the new cloud infrastructure, it identifies the broad security requirements of the application, as well as the security capabilities of the new environment. Using this information, the security assurance service computes a minimal security environment needed by the cloud application for the burst operation. The security assurance service then configures the necessary topology in the new cloud environment, and the burst operation is then completed by having the cloud application deployed in that topology.