Secure Application Zones for Cloud Bursting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing, application developers face challenges in evaluating and ensuring the security of their applications during deployment, especially when bursting into new cloud infrastructures with different security capabilities, leading to potential security risks and complexities.
Innovation Solution
A security assurance service is introduced to create and manage secure application zones within cloud infrastructures, which identifies security requirements and capabilities in the new environment, computes the minimal security needs, and configures the necessary topology to ensure secure deployment during cloud bursting operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If application developers are empowered with operational capability in virtualized environments, then deployment flexibility improves, but security evaluation capability deteriorates due to lack of security background knowledge
Solution Approach 1:
The patent introduces a security assurance service as an intermediary between application developers and the complex security infrastructure. This service automatically evaluates security requirements, analyzes cloud environment capabilities, and configures secure application zones without requiring developers to have security expertise. The intermediary translates developer intent into security configurations, resolving the contradiction between deployment flexibility and security evaluation capability.
2Productivity
If cloud bursting is implemented to meet peak demand, then productivity improves, but security risk increases due to different security capabilities in target environments
Solution Approach 1:
The patent implements preliminary action by having the security assurance service pre-evaluate security requirements of applications and pre-analyze security capabilities of potential cloud burst target environments before actual bursting occurs. This advance preparation ensures that security configurations are ready and compatible, preventing security inconsistencies when applications burst to cloud environments with different security capabilities.
Solution Approach 2:
The patent dynamically adjusts security configuration parameters based on the specific cloud environment being targeted for bursting. The security assurance service analyzes the security capabilities of the target environment and modifies security zone configurations to match and maintain security consistency across different cloud infrastructures, enabling productive cloud bursting while maintaining security reliability.
3Reliability
If manual security configuration is performed by security experts, then security reliability improves, but device complexity increases due to increasingly complex security software deployments
Solution Approach 1:
The patent implements self-service by enabling the security assurance service to automatically configure secure application zones without requiring manual intervention from security experts. The service autonomously evaluates security requirements, analyzes cloud environment capabilities, computes minimal security environments, and configures security topologies. This automation maintains security reliability while dramatically reducing deployment complexity and making security management accessible to application developers.
Data Source
AI summary
A cloud infrastructure security assurance service is enhanced to facilitate bursting of cloud applications into other cloud infrastructures. The security assurance service provides a mechanism to enable creation and management of secure application zones within a cloud infrastructure. When the security assurance service receives an indication that a workload associated with a cloud application triggers a cloud burst, the service is extended into a new cloud infrastructure. Once the security assurance service is instantiated in the new cloud infrastructure, it identifies the broad security requirements of the application, as well as the security capabilities of the new environment. Using this information, the security assurance service computes a minimal security environment needed by the cloud application for the burst operation. The security assurance service then configures the necessary topology in the new cloud environment, and the burst operation is then completed by having the cloud application deployed in that topology.


