IP Library Granted Patent US 9,563,460
Granted Patent B2
US 9,563,460 · App. 14/691,034 · Granted Feb 7, 2017

Enforcement of compliance policies in managed virtual systems

Inventors: Joseph Fitzgerald (Franklin Lakes, NJ); Oleg Barenboim (Fort Lee, NJ)
Assignee: MANAGEIQ, Inc.
G06F9/45558G06F9/45537G06F9/542G06F11/0712G06F11/0727G06F11/0751G06F11/0793G06F11/0766G06F2009/4557G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,563,460
App. No.
14/691,034
Granted
Feb 7, 2017
Kind
B2
Abstract

Techniques are disclosed for controlling and managing virtual machines and other such virtual systems. VM execution approval is based on compliance with policies controlling various aspects of VM. The techniques can be employed to benefit all virtual environments, such as virtual machines, virtual appliances, and virtual applications. For ease of discussion herein, assume that a virtual machine (VM) represents each of these environments. In one particular embodiment, a systems management partition (SMP) is created inside the VM to provide a persistent and resilient storage for management information (e.g., logical and physical VM metadata). The SMP can also be used as a staging area for installing additional content or agentry on the VM when the VM is executed. Remote storage of management information can also be used. The VM management information can then be made available for pre-execution processing, including policy-based compliance testing.

Claims (40)

1. An apparatus for enforcing a policy associated with a virtual appliance, the apparatus comprising:

a memory device storing instructions; and

a computing device communicatively coupled to a virtual appliance, the computing device including a processor operably coupled to the memory device, the processor executing the instructions to:

receive a virtual appliance event request;

receive first data from within the virtual appliance in response to receiving the virtual appliance event request, wherein the first data was extracted from within the virtual appliance prior to receiving the virtual appliance event request, and the first data was stored prior to receiving the virtual appliance event request for later processing after receiving the virtual appliance event request;

receive second different data from an environment outside the virtual appliance in response to receiving the virtual appliance event request;

determine whether an internal non-compliance by the virtual appliance of a first policy-based compliance scheme exists based on the first data that was stored prior to receiving the virtual appliance event request;

determine whether an external non-compliance by the virtual appliance as provided in the environment of a second different policy-based compliance scheme exists based on the second different data; and

in response to determining that at least one of an internal non-compliance and an external non-compliance exists, deny the virtual appliance event request.

2. The apparatus of claim 1 , wherein the virtual appliance event request includes a stop virtual appliance request.

3. The apparatus of claim 1 , wherein the virtual appliance event request includes a pause virtual appliance request.

4. The apparatus of claim 1 , wherein the virtual appliance event request includes a move virtual appliance request.

5. The apparatus of claim 1 , wherein the virtual appliance event request includes a clone virtual appliance request.

6. The apparatus of claim 1 , wherein the virtual appliance event request includes a create new virtual appliance request.

7. The apparatus of claim 1 , wherein the virtual appliance event request includes a deploy virtual appliance from template request.

8. The apparatus of claim 1 , wherein the internal non-compliance includes at least one of software that has not been installed on the virtual appliance, software that has been removed from the virtual appliance, and software that has not been updated on the virtual appliance.

9. The apparatus of claim 1 , wherein the environment is at least one of a virtual machine manager, a host environment, a management agent, and an execution platform.

10. A computer implemented method for enforcing a policy associated with a virtual appliance, the method comprising:

receiving a virtual appliance event request;

receiving first data from within the virtual appliance in response to receiving the virtual appliance event request, wherein the first data was extracted from within the virtual appliance prior to receiving the virtual appliance event request, and the first data was stored prior to receiving the virtual appliance event request for later processing after receiving the virtual appliance event request;

receiving second different data from an environment outside the virtual appliance in response to receiving the virtual appliance event request;

determining whether an internal non-compliance by the virtual appliance of a first policy-based compliance scheme exists based on the first data that was stored prior to receiving the virtual appliance event request;

determining whether an external non-compliance by the virtual appliance as provided in the environment of a second different policy-based compliance scheme exists based on the second different data; and

in response to determining that at least one of an internal non-compliance and an external non-compliance exists, denying the virtual appliance event request.

11. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a stop virtual appliance request.

12. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a pause virtual appliance request.

13. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a move virtual appliance request.

14. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a clone virtual appliance request.

15. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a create new virtual appliance request.

16. The computer implemented method of claim 10 , wherein the virtual appliance event request includes a deploy virtual appliance from template request.

17. The computer implemented method of claim 10 , wherein the internal non-compliance includes at least one of software that has not been installed on the virtual appliance, software that has been removed from the virtual appliance, and software that has not been updated on the virtual appliance.

18. The computer implemented method of claim 10 , wherein the environment is at least one of a virtual machine manager, a host environment, a management agent, and an execution platform.

19. A non-transitory computer readable medium storing instructions for enforcing a policy associated with a virtual appliance, which when executed by a processor, cause the processor to:

receive a virtual appliance event request;

receive first data from within the virtual appliance in response to receiving the virtual appliance event request, wherein the first data was extracted from within the virtual appliance prior to receiving the virtual appliance event request, and the first data was stored prior to receiving the virtual appliance event request for later processing after receiving the virtual appliance event request;

receive second different data from an environment outside the virtual appliance in response to receiving the virtual appliance event request;

determine whether an internal non-compliance by the virtual appliance of a first policy-based compliance scheme exists based on the first data that was stored prior to receiving the virtual appliance event request;

determine whether an external non-compliance by the virtual appliance as provided in the environment of a second different policy-based compliance scheme exists based on the second different data; and

in response to determining that at least one of an internal non-compliance and an external non-compliance exists, deny the virtual appliance event request.

20. The non-transitory computer readable medium of claim 19 , wherein determining at least one of the internal non-compliance and the external non-compliance includes computing signatures used for comparison using at least one hashing function.

Assignments (2)
MERGER Recorded Apr 5, 2018
From: MANAGEIQ, INC.
To: RED HAT, INC.
Reel/Frame 045445/0665 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2015
From: FITZGERALD, JOSEPH J.; BARENBOIM, OLEG
To: MANAGEIQ, INC.
Reel/Frame 037329/0829 →
Continuity (3)
Continuation 11945927 · Nov 27, 2007
Continuation In Part 11550364 · Oct 17, 2006
Related Publication 20150227386A1 · Aug 13, 2015