Workload Sensitivity Assessment for Virtual Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual data centers, administrators face challenges in accurately applying security policies to workloads due to the complexity of managing computing resources and identifying sensitive data, leading to inconsistent protection of sensitive information.

Innovation Solution

A computer-implemented method and system that identifies virtual data centers hosting multiple workloads sharing a common computing infrastructure, performs sensitivity assessments on workloads based on attributes of allocated resources, and applies security policies accordingly, ensuring accurate protection of sensitive data by analyzing the underlying computing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional technologies are used to tag workloads with security policies, then the security policy application process is simple, but the accuracy of tagging all workloads based on data accessed is insufficient

Engineering Contradiction:
Improveaccuracy of workload taggingVSAvoidcomplexity of security policy application
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the security policy application process into multiple stages: (1) identifying workloads and their associated data, (2) assessing sensitivity of data and workloads, (3) applying security policies based on sensitivity assessments. This segmentation allows accurate tagging by breaking down the complex task of analyzing all workloads and their data access patterns into manageable segments, each handled by specialized modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces sensitivity assessment as an intermediary step between workload identification and security policy application. The sensitivity assessment module analyzes data characteristics and workload interactions to determine sensitivity levels, which then mediates the selection of appropriate security policies. This intermediary ensures accurate tagging by providing a systematic evaluation of data sensitivity before policy application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If sensitivity assessment is performed on all workloads based on data accessed, then the accuracy of security policy application is improved, but the time required for assessment increases

Engineering Contradiction:
Improveaccuracy of sensitivity assessmentVSAvoidtime for sensitivity assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining sensitivity levels and security policies before actual workload assessment. Sensitivity thresholds and policy templates are established in advance, allowing the sensitivity assessment module to quickly evaluate workloads against predefined criteria rather than conducting comprehensive analysis from scratch, thus reducing assessment time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial action by assessing only the necessary attributes of workloads and data to determine sensitivity levels. Instead of performing exhaustive analysis of all workload operations and data access patterns, the system focuses on key indicators such as data types, access patterns, and workload criticality, achieving sufficient accuracy without the time cost of complete analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security policies are applied to all computing resources, then the protection of sensitive data is comprehensive, but the complexity of managing computing resources increases

Engineering Contradiction:
Improvecomprehensive protection of sensitive dataVSAvoidcomplexity of computing resource management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by tailoring security policies to specific workloads and data based on their individual sensitivity levels. Rather than applying uniform security measures to all computing resources, the system adjusts policy stringency and type according to the local characteristics of each workload-data combination, achieving comprehensive protection where needed while reducing complexity in less critical areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamics by making security policy application adaptive and flexible rather than static. The sensitivity assessment continuously monitors workload characteristics and data access patterns, dynamically adjusting security policy application in real-time. This dynamic approach allows comprehensive protection of sensitive data while simplifying management by automatically adapting to changing conditions without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9021546B1Systems and methods for workload security in virtual data centers
Publication Date: 2015.04.28 CA TECH INC
  • US9021546B1 patent drawing
  • US9021546B1 patent drawing
  • US9021546B1 patent drawing

AI summary

A computer-implemented method for workload security in virtual data centers may include (1) identifying a virtual data center that hosts a plurality of workloads sharing a common computing infrastructure, (2) identifying a workload within the plurality of workloads that is subject to a sensitivity assessment that pertains to an application of at least one security policy to at least one computing resource used by the workload, (3) performing the sensitivity assessment for the workload based at least in part on an attribute of an allocated resource within the common computing infrastructure provisioned to the workload, and (4) applying the security policy to the computing resource based at least in part on the sensitivity assessment for the workload. Various other methods, systems, and encoded computer-readable media are also disclosed.