Tag-Based Policy Architecture for Virtualized Resource Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualized computing environments face challenges in dynamically managing access to virtualized resources due to static, non-human-readable configuration methods based on IP address-based tables and VLANs, which are inefficient and difficult to update in changing environments.
Innovation Solution
A tag-based policy architecture using cryptographically-verifiable metadata, such as JSON Web Tokens (JWTs) and network certificates, is implemented to authenticate and authorize access to virtualized resources, enabling fine-grained control and unified policy management across a virtualized computing environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If address-based tables and VLANs are used for access control, then network segmentation is achieved, but access control is coarse-grained and difficult to update dynamically
Solution Approach 1:
The patent changes the fundamental parameter of access control from static IP address-based rules to dynamic tag-based policies. Tags can be assigned and removed programmatically, allowing access control parameters to change dynamically without reconfiguring network infrastructure. This resolves the contradiction by enabling adaptability while maintaining ease of operation through software-based tag management.
Solution Approach 2:
The system transitions from static VLAN configurations to dynamic policy enforcement where access rights are determined by tags that can be added or removed in real-time. The policy engine continuously evaluates tag combinations against defined policies, enabling dynamic adaptation to changing access requirements without manual network reconfiguration.
2Productivity
If manual configuration of firewall rules and VLANs is used, then access control is enforced, but the process is time-consuming and inefficient
Solution Approach 1:
The system enables self-service automation where tags are automatically assigned to resources based on predefined policies and resource attributes. The policy engine automatically evaluates tag combinations and enforces access control without manual intervention, dramatically improving productivity and eliminating time-consuming manual configuration of firewall rules and VLAN assignments.
Solution Approach 2:
Access control policies are pre-configured with tag-based rules before resources are deployed. When resources are created or modified, their tags are automatically evaluated against pre-defined policies, enabling preliminary action that prevents unauthorized access before it occurs and eliminates the need for time-consuming post-deployment configuration adjustments.
3Manufacturing precision
If network layer address-based control is used, then access enforcement is simple, but fine-grained control over virtualized resources is not achieved
Solution Approach 1:
The patent segments access control into multiple independent tag dimensions, where each tag represents a specific attribute or role. This segmentation enables fine-grained control by combining multiple tags to define precise access permissions, while the policy engine manages the complexity by evaluating tag combinations against structured policies rather than requiring complex network layer configurations.
Solution Approach 2:
The policy engine acts as an intermediary layer between the simple tag assignment and the complex access control decisions. It translates high-level policy definitions into specific access enforcement actions, achieving fine-grained control without exposing the complexity of policy management to users who only need to assign and remove tags.
4Adaptability or versatility
If static VLAN configurations are used, then network security is maintained, but the system cannot adapt to dynamically changing environments
Solution Approach 1:
The system implements continuous feedback loops where the policy engine monitors tag assignments and automatically adjusts access permissions based on current policy definitions and resource states. This feedback mechanism maintains security reliability by continuously evaluating access requests against up-to-date policies while enabling adaptability to dynamically changing environments through automated policy enforcement.
Data Source
AI summary
A tag-based policy architecture enforces information technology (IT) policy in a virtualized computing environment using cryptographically-verifiable metadata to authenticate compute resources coupled to a computer network and to authorize access to protected resources of the network. The compute resources are illustratively virtual machine instances (VMIs) provided by a virtual data center (VDC) of the environment, whereas the protected resources are illustratively virtualized storage, network and/or other compute resources of the VDC. Each VMI includes an intermediary manager, e.g., metavisor. The tag-based policy architecture includes an infrastructure having a centralized policy decision end point (e.g., a control plane of the VDC) and distributed policy enforcement endpoints (e.g., metavisors of the VMIs) to provide end-to-end passing of the cryptographically-verifiable metadata to (i) authorize instantiation of the VMIs at the control plane, and (ii) enforce access to the virtualized resources at the metavisors.


