IP Library Granted Patent US 9,275,004
Granted Patent B2
US 9,275,004 · App. 13/710,642 · Granted Mar 1, 2016

Hybrid firewall for data center security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,275,004
App. No.
13/710,642
Granted
Mar 1, 2016
Kind
B2
Abstract

A system and method for managing a hybrid firewall solution, employing both hardware and software firewall components, for a cloud computing data center is provided. A virtual application is hosted by a first plurality of application virtual machines and a second plurality of firewall virtual machines provides firewalling services for traffic associated with the virtual application. A cloud management entity determines that the virtual application requires an increased number of application virtual machines. A security profile for the virtual application is verified to determine if an increased number of firewall virtual machines is required by the increased number of application virtual machines. The cloud management entity can instantiate additional application virtual machines and firewall virtual machines as required.

Claims (29)

1. A method for managing firewall requirements related to a

virtualized application by a cloud management entity having a processing engine, comprising:

responsive to determining, by the processing engine, that a virtualized application, associated with a first plurality of application virtual machines and a second plurality of firewall virtual machines, requires an increased number of application virtual machines in the first plurality, instantiating an application virtual machine;

comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a bandwidth capacity of the firewall virtual machines in the second plurality to determine whether a firewall ratio is exceeded by the increased number of application virtual machines; and

responsive to determining, by the processing engine, that the firewall ratio is exceeded, instantiating a firewall virtual machine.

2. The method of claim 1 , wherein the firewall ratio threshold is included in an application profile configured at deployment of the virtualized application.

3. The method of claim 1 , further including the step of comparing the required increased number of application virtual machines to the number of firewall virtual machines in the second plurality.

4. The method of claim 1 , further including the steps of:

computing a ratio of the required increased number of application virtual machines to the number of firewall virtual machines in the second plurality; and

comparing the computed ratio with a firewall ratio requirement associated with the virtualized application.

5. The method of claim 1 , further including the step of comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a sum of a bandwidth capacity of the firewall virtual machines in the second plurality and a bandwidth of a hardware firewall provisioned for use by the virtualized application.

6. The method of claim 1 , wherein the virtualized application is hosted on the first plurality of application virtual machines and the second plurality of firewall virtual machines provide firewalling services for traffic associated with the virtualized application.

7. The method of claim 1 , further including the steps of adding the instantiated application virtual machine to the first plurality; and adding the instantiated firewall virtual machine to the second plurality.

8. The method of claim 1 , further including responsive to determining that an increased number of load balancing virtual machines is required by the increased number of application virtual machines, instantiating a load balancing virtual machine.

9. The method of claim 1 , further including the steps of:

determining that the virtualized application requires a decreased number of application virtual machines in the first plurality;

determining that a decreased number of firewall virtual machines is required by the decreased number of application virtual machines;

shutting down an application virtual machine; and

shutting down a firewall virtual machine.

10. A cloud management entity, comprising:

a memory for storing instructions; and

a processing engine, configured to execute the instructions, for, responsive to

determining that a virtualized application, associated with a first plurality of application virtual machines and a second plurality of firewall virtual machines, requires an increased number of application virtual machines in the first plurality, instantiating an application virtual machine; for comparing a bandwidth capacity of the required increased number of application virtual machines in the first plurality to a bandwidth capacity of the firewall virtual machines in the second plurality to determine whether a firewall ratio is exceeded by the increased number of application virtual machines; and for, responsive to determining that the firewall ratio is exceeded, instantiating a firewall virtual machine.

11. The cloud management entity of claim 10 , further comprising a communication interface for communicating with the first plurality of application virtual machines and the second plurality of firewall virtual machines.

12. The cloud management entity of claim 10 , wherein the firewall ratio threshold is included in an application profile configured at deployment of the virtualized application by the processing engine.

13. The cloud management entity of claim 10 , wherein the processing engine compares the required increased number of application virtual machines in the first plurality to the number of firewall virtual machines in the second plurality.

14. The cloud management entity of claim 10 , wherein the processing engine computes a ratio of the required increased number of application virtual machines in the first plurality to the number of firewall virtual machines in the second plurality; and compares the computed ratio to a firewall ratio threshold associated with the virtualized application.

15. The cloud management entity of claim 10 , wherein the processing engine compares a bandwidth capacity of the increased number of application virtual machines in the first plurality to a sum of a bandwidth capacity of the firewall virtual machines in the second plurality and a bandwidth capacity of a hardware firewall provisioned for use by the virtualized application.

16. The cloud management entity of claim 10 , wherein the virtualized application is hosted on the first plurality of application virtual machines and the second plurality of firewall virtual machines provide firewalling services for traffic associated with the virtualized application.

Assignments (5)
SECURITY AGREEMENT Recorded Apr 24, 2025
From: NOVACLOUD LICENSING LLC
To: NCLD1 LLC
Reel/Frame 071033/0001 →
SECURITY AGREEMENT Recorded Apr 18, 2025
From: NOVACLOUD LICENSING LLC
To: NCLD1 LLC
Reel/Frame 070888/0066 →
SECURITY INTEREST Recorded Feb 13, 2025
From: NOVACLOUD LICENSING LLC
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 070226/0533 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2024
From: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
To: NOVACLOUD LICENSING LLC
Reel/Frame 068522/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2013
From: ZHU, ZHONGWEN; POURZANDI, MAKAN
To: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
Reel/Frame 029996/0370 →