IP Library Granted Patent US 7,827,294
Granted Patent B2
US 7,827,294 · App. 10/711,433 · Granted Nov 2, 2010

System and method for dynamic security provisioning of computing resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,827,294
App. No.
10/711,433
Granted
Nov 2, 2010
Kind
B2
Abstract

The present invention facilitates the dynamic provisioning of computing and data assets in a commodity computing environment. The invention provides a system and method for dynamically provisioning and de-provisioning computing resources based on multi-dimensional decision criteria. By employing specialized computing components configured to assess an asset and requestor of an asset, a provisioning engine is able to transform the input from the computing components into a specific configuration of computing resource provisioning and security controls. According to the rules and policies applying to a security domain, the provisioning engine may dynamically allocate computing resources in a manner that is both safe and efficient for the asset.

Claims (40)

1. A method, comprising:

receiving, by a computer based system for dynamically provisioning computing resources, a request for a computing resource, wherein said request is associated with an asset;

determining, by said computer based system, an asset classification of said asset, a business value of said asset, and a resource classification related to said asset,

wherein said asset classification is at least one of: a public asset, a business confidential asset, a private asset, and a secret asset,

wherein said business value of said asset is one of: a low value, a medium value, and a high value, and

wherein said resource classification is one of: a trusted classification for internal entities and a non-trusted classification for external entities;

dynamically assigning, by said computer based system, said asset to one of a plurality of security domains based on at least (1) a source of said request and (2) said determining, wherein each security domain corresponds to a different degree of security control; and

applying, by said computer based system, encryption to asset data based on said asset classification;

provisioning, by said computer based system, said computing resource based on said one of said plurality of security domains.

2. The method of claim 1 , further comprising determining, by said computer based system, a data classification of said asset.

3. The method of claim 1 , further comprising de-provisioning, by said computer based system, said computing resource.

4. The method of claim 1 , further comprising de-provisioning, by said computer based system, said computing resource when said computing resource is no longer needed by said asset.

5. The method of claim 1 , further comprising verifying, by said computer based system, a software inventory of at least one of: an internal client and an external client.

6. The method of claim 1 , further comprising defining, by said computer based system, which processes may be suspended if said asset requires an additional computing resource.

7. The method of claim 1 , further comprising storing, by said computer based system, policies regarding processing assets when computing resources are limited due to a failure of at least one of: software and hardware.

8. The method of claim 1 , further comprising determining a geographical source from which said request originates and applying at least one of a patch and a privacy rule based on said geographical source determination.

9. A machine-readable non-transitory medium having stored thereon a plurality of instructions that, when executed by a computer based system for dynamically provisioning computing resources, cause said computer based system to perform operations comprising:

receiving, by said computer system, a request for a computing resource, wherein said request is associated with an asset;

determining, by said computer based system, an asset classification of said asset, a business value of said asset, and a resource classification related to said asset,

wherein said asset classification is at least one of: a public asset, a business confidential asset, a private asset, and a secret asset,

wherein said business value of said asset is one of: a low value, a medium value, and a high value, and

wherein said resource classification is one of: a trusted classification for internal entities and a non-trusted classification for external entities;

dynamically assigning, by said computer based system, said asset to one of a plurality of security domains based on at least (1) a source of said request and (2) said determining-step, wherein each security domain corresponds to a different degree of security control; and

applying, by said computer based system, encryption to asset data based on said asset classification;

provisioning, by said computer based system, said computing resource based on said one of said plurality of security domains.

10. A system configured to facilitate dynamic provisioning of computing resources, said system comprising a provisioning engine having a memory and processor, said provisioning engine configured to:

receive a request for a computing resource, wherein said request is associated with an asset,

determine an asset classification, a business value of said asset, and a resource classification related to said asset based upon input from a manager component,

wherein said asset classification is at least one of: a public asset, a business confidential asset, a private asset, and a secret asset,

wherein said business value of said asset is one of: a low value, a medium value, and a high value, and

wherein said resource classification is one of: a trusted classification for internal entities and a non-trusted classification for external entities;

dynamically assign said asset to one of a plurality of security domains based on at least (1) a source of said request and (2) said determining step, wherein each security domain corresponds to a different degree of security control; and

apply encryption to asset data based on said asset classification, wherein said encryption is applied by a policy manager instruction module;

provision said computing resource based on said one of said plurality of security domains.

11. The system of claim 10 , further comprising a server configured to communicate with at least one of: an internal and an external client.

12. The system of claim 10 , further comprising a domain database configured to store domain rules and policies.

13. The system of claim 10 , further comprising a connection manager instruction module configured to direct at least one of: an internal client and an external client to comply with software requirements.

14. The system of claim 10 , further comprising a configuration manager instruction module configured to identify which processes may be suspended if an asset requires additional computing resource.

15. The system of claim 10 , further comprising a risk manager instruction module configured to verify software inventory of at least one of: an internal client and an external client.

16. The system of claim 10 , further comprising a recovery manager instruction module configured to store policies regarding processing assets when computing resources are limited due to at least one of: an equipment failure and a software failure.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2018
From: III HOLDINGS 1, LLC
To: LIBERTY PEAK VENTURES, LLC
Reel/Frame 045611/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2014
From: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
To: III HOLDINGS 1, LLC
Reel/Frame 032722/0746 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2004
From: MERKOW, MARK; PETRONE, JAMES F.
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 015146/0112 →