IP Library Granted Patent US 8,689,282
Granted Patent B1
US 8,689,282 · App. 13/336,692 · Granted Apr 1, 2014

Security policy enforcement framework for cloud-based information processing systems

Inventors: Alina M. Oprea (Arlington, MA); Yinqian Zhang (Chapel Hill, NC); Vijay Ganti (Lexington, MA); John P. Field (Chatham, NJ); Ari Juels (Brookline, MA); Michael Kendrick Reiter (Chapel Hill, NC)
Assignees: EMC Corporation; University of North Carolina at Chapel Hill
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,282
App. No.
13/336,692
Filed
Dec 23, 2011
Granted
Apr 1, 2014
Kind
B1
Art Unit
2434
USPC
726/1
Abstract

Cloud infrastructure of a cloud service provider comprises a processing platform implementing a security policy enforcement framework. The security policy enforcement framework comprises a policy analyzer that is configured to identify at least one security policy associated with at least one tenant of the cloud service provider, to analyze the security policy against configuration information characterizing the cloud infrastructure of the cloud service provider, and to control execution of one or more applications of said at least one tenant within the cloud infrastructure in accordance with the security policy, based at least in part on one or more results of the analysis of the security policy. The security policy enforcement framework may be implemented in a platform-as-a-service (PaaS) layer of the cloud infrastructure, and may comprise a runtime controller, an operating system controller, a hypervisor controller and a PaaS controller.

Claims (34)

1. A method comprising:

identifying at least one security policy associated with a given tenant of a cloud service provider;

analyzing the security policy against configuration information characterizing cloud infrastructure of the cloud service provider, the cloud infrastructure comprising physical infrastructure and associated virtualization infrastructure running on the physical infrastructure; and

controlling execution of one or more applications of the given tenant within the cloud infrastructure of the cloud service provider in accordance with the security policy based at least in part on one or more results of the analyzing step;

wherein the identifying, analyzing and controlling steps are implemented in a security policy enforcement framework of a processing platform of the cloud infrastructure; and

wherein the security policy associated with the given tenant comprises one or more tenant-specified rules related to isolation of the given tenant with respect to one or more other tenants of the cloud service provider.

2. The method of claim 1 wherein said at least one security policy incorporates at least one of tenant requirement information and service provider enforcement information.

3. The method of claim 1 wherein the analyzing step is implemented in a policy analyzer of the security policy enforcement framework and further comprises determining if the security policy is enforceable based on the configuration information characterizing the cloud infrastructure, and if the security policy is enforceable determining control information to be provided by the policy analyzer to one or more controllers of the security policy enforcement framework to carry out the security policy.

4. The method of claim 3 wherein said one or more controllers comprise at least a runtime controller configured to interface with runtime environments of said one or more applications.

5. The method of claim 4 wherein the runtime environments comprise a virtual machine runtime environment and at least one other runtime environment.

6. The method of claim 3 wherein said one or more controllers comprise at least an operating system controller associated with an operating system utilized by runtime environments of said one or more applications.

7. The method of claim 3 wherein said one or more controllers comprise at least a hypervisor controller configured to interface with a hypervisor that implements a virtual machine utilized by said one or more applications.

8. The method of claim 3 wherein said security policy enforcement framework is implemented in a platform-as-a-service (PaaS) layer of the cloud infrastructure and said one or more controllers comprise at least a PaaS controller configured to interface with a PaaS fabric of the PaaS layer.

9. The method of claim 3 further comprising the step of providing a report from the policy analyzer to the given tenant regarding enforcement of said at least one security policy, wherein the report is provided under the control of a management component of the security policy enforcement framework.

10. The method of claim 3 further comprising the step of determining the configuration information in the policy analyzer based on information received from said one or more controllers.

11. The method of claim 1 wherein the security policy specifies that applications associated with the given tenant are restricted from reading files associated with other tenants.

12. The method of claim 1 wherein the security policy specifies that applications associated with the given tenant only communicate with applications that belong to the given tenant.

13. The method of claim 1 wherein the security policy specifies that an application associated with the given tenant only be scheduled on a physical machine on which no other instances of the same application are running.

14. A computer program product comprising a non-transitory processor-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by the processing platform cause the processing platform to perform the steps of the method of claim 1 .

15. An apparatus comprising:

a processing platform comprising at least one processing device having a processor coupled to a memory, said processing platform implementing a security policy enforcement framework for cloud infrastructure of a cloud service provider;

wherein the security policy enforcement framework comprises a policy analyzer configured to identify at least one security policy associated with a given tenant of the cloud service provider, to analyze the security policy against configuration information characterizing cloud infrastructure of the cloud service provider, and to control execution of one or more applications of the given tenant within the cloud infrastructure of the cloud service provider in accordance with the security policy based at least in part on one or more results of the analysis of the security policy;

wherein the cloud infrastructure comprises physical infrastructure and associated virtualization infrastructure running on the physical infrastructure; and

wherein the security policy associated with the given tenant comprises one or more tenant-specified rules related to isolation of the given tenant with respect to one or more other tenants of the cloud service provider.

16. The apparatus of claim 15 wherein the policy analyzer is configured to determine if the security policy is enforceable based on the configuration information characterizing the cloud infrastructure, and if the security policy is enforceable, to determine control information to be provided by the policy analyzer to one or more controllers of the security policy enforcement framework to carry out the security policy.

17. The apparatus of claim 16 wherein said one or more controllers comprise one or more of:

a runtime controller configured to interface with runtime environments of said one or more applications;

an operating system controller associated with an operating system utilized by the runtime environments of said one or more applications; and

a hypervisor controller configured to interface with a hypervisor that implements a virtual machine utilized by said one or more applications.

18. The apparatus of claim 16 wherein said security policy enforcement framework is implemented in a platform-as-a-service (PaaS) layer of the cloud infrastructure and said one or more controllers comprise at least a PaaS controller configured to interface with a PaaS fabric of the PaaS layer.

19. The apparatus of claim 16 wherein the policy analyzer is configured to determine the configuration information based on information received from said one or more controllers.

20. A cloud-based information processing system comprising the apparatus of claim 15 .

21. The method of claim 1 wherein the configuration information comprises information characterizing at least one of an application layer, a platform-as-a-service (PaaS) layer and an infrastructure-as-a-service (IaaS) layer of the virtualization infrastructure.

22. The method of claim 4 wherein the runtime environments comprise a first runtime environment utilizing a first programming language and at least a second runtime environment utilizing a second programming language different than the first programming language.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
CONFIRMATORY LICENSE Recorded Sep 25, 2015
From: UNIVERSITY OF NORTH CAROLINA, CHAPEL HILL
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 036689/0462 →
CONFIRMATORY LICENSE Recorded Apr 27, 2015
From: UNIVERSITY OF NORTH CAROLINA AT CHAPEL HILL
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 035506/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2012
From: ZHANG, YINQIAN; REITER, MICHAEL KENDRICK
To: UNIVERSITY OF NORTH CAROLINA AT CHAPEL HILL
Reel/Frame 027870/0226 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2012
From: OPREA, ALINA M.; GANTI, VIJAY; FIELD, JOHN P.; JUELS, ARI
To: EMC CORPORATION
Reel/Frame 027870/0017 →