Tag-Based Policy Architecture for Virtualized Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualized computing environments face challenges in dynamically managing access to virtualized resources due to static, non-human-readable configuration methods based on IP address-based tables and VLANs, which are inefficient and difficult to update in changing environments.

Innovation Solution

A tag-based policy architecture using cryptographically-verifiable metadata, such as JSON Web Tokens (JWTs) and network certificates, is implemented to authenticate and authorize access to virtualized resources, enabling fine-grained control and unified policy management across a virtualized computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If address-based tables and VLANs are used for access control, then network segmentation is achieved, but access control is coarse-grained and difficult to update dynamically

Engineering Contradiction:
Improvedynamic access controlVSAvoidconfiguration update difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent changes the fundamental parameter of access control from static IP address-based rules to dynamic tag-based policies. Tags can be assigned and removed programmatically, allowing access control parameters to change dynamically without reconfiguring network infrastructure. This resolves the contradiction by enabling adaptability while maintaining ease of operation through software-based tag management.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system transitions from static VLAN configurations to dynamic policy enforcement where access rights are determined by tags that can be added or removed in real-time. The policy engine continuously evaluates tag combinations against defined policies, enabling dynamic adaptation to changing access requirements without manual network reconfiguration.

Inventive Principle:
Principle #15Dynamics

2Productivity

If manual configuration of firewall rules and VLANs is used, then access control is enforced, but the process is time-consuming and inefficient

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidconfiguration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service automation where tags are automatically assigned to resources based on predefined policies and resource attributes. The policy engine automatically evaluates tag combinations and enforces access control without manual intervention, dramatically improving productivity and eliminating time-consuming manual configuration of firewall rules and VLAN assignments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access control policies are pre-configured with tag-based rules before resources are deployed. When resources are created or modified, their tags are automatically evaluated against pre-defined policies, enabling preliminary action that prevents unauthorized access before it occurs and eliminates the need for time-consuming post-deployment configuration adjustments.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If network layer address-based control is used, then access enforcement is simple, but fine-grained control over virtualized resources is not achieved

Engineering Contradiction:
Improveaccess control granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into multiple independent tag dimensions, where each tag represents a specific attribute or role. This segmentation enables fine-grained control by combining multiple tags to define precise access permissions, while the policy engine manages the complexity by evaluating tag combinations against structured policies rather than requiring complex network layer configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policy engine acts as an intermediary layer between the simple tag assignment and the complex access control decisions. It translates high-level policy definitions into specific access enforcement actions, achieving fine-grained control without exposing the complexity of policy management to users who only need to assign and remove tags.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If static VLAN configurations are used, then network security is maintained, but the system cannot adapt to dynamically changing environments

Engineering Contradiction:
Improveenvironment adaptabilityVSAvoidsecurity enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements continuous feedback loops where the policy engine monitors tag assignments and automatically adjusts access permissions based on current policy definitions and resource states. This feedback mechanism maintains security reliability by continuously evaluating access requests against up-to-date policies while enabling adaptability to dynamically changing environments through automated policy enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10999328B2Tag-based policy architecture
Publication Date: 2021.05.04 VMWARE INC
  • US10999328B2 patent drawing
  • US10999328B2 patent drawing
  • US10999328B2 patent drawing

AI summary

A tag-based policy architecture enforces information technology (IT) policy in a virtualized computing environment using cryptographically-verifiable metadata to authenticate compute resources coupled to a computer network and to authorize access to protected resources of the network. The compute resources are illustratively virtual machine instances (VMIs) provided by a virtual data center (VDC) of the environment, whereas the protected resources are illustratively virtualized storage, network and/or other compute resources of the VDC. Each VMI includes an intermediary manager, e.g., metavisor. The tag-based policy architecture includes an infrastructure having a centralized policy decision end point (e.g., a control plane of the VDC) and distributed policy enforcement endpoints (e.g., metavisors of the VMIs) to provide end-to-end passing of the cryptographically-verifiable metadata to (i) authorize instantiation of the VMIs at the control plane, and (ii) enforce access to the virtualized resources at the metavisors.