Trusted public infrastructure grid cloud
Abstract
Systems and methods of implementing a secured cloud environment allow for design and instantiation of a security policy at the infrastructure level. An example system may comprise a first module to facilitate selecting at least two cloud computing component templates from a cloud computing component catalog. The system may comprise a second module to facilitate defining a connection between the at least two selected cloud computing component templates. The system may comprise a third module to facilitate assigning a security level and a policy to at least one of the at least two selected cloud computing component templates. The system may comprise a fourth module to facilitate building a cloud computing component blueprint.
Claims
exact text as granted — not AI-modified1 . A system comprising:
a processor; a computer readable storage medium having computer readable instructions, the instructions executable by the processor to cause the system to:
select a first security policy for a first cloud computing component, wherein the first security policy indicates a plurality of security requirements;
deploy the first cloud computing component along with an agent to monitor whether the first cloud computing component complies with the plurality of security requirements;
receive first security compliance information from the agent; and
in response to a determination that the first security compliance information indicates that the deployed first cloud computing component does not comply with a first security requirement of the plurality of security requirements,
indicate that the first cloud computing component does not comply with the first security policy; and
modify the deployed first cloud computing component to comply with the first security requirement;
receive second security compliance information from the agent; and
in response to a determination that the second security compliance information indicates that the deployed first cloud computing component complies with the plurality of security requirements, indicate that the first cloud computing component complies with the first security policy.
2 . (canceled)
3 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to:
select a cloud computing component template from a cloud computing component template catalog, wherein the cloud computing component template corresponds to the first cloud computing component; wherein the instructions executable by the processor to cause the system to modify the deployed first cloud computing component to comply with the first security requirement comprise instructions executable by the processor to cause the system to modify the cloud computing component template and redeploy the first cloud computing component in accordance with the modified cloud computing component template.
4 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to create a cloud computing application blueprint, wherein the blueprint comprises information regarding the first security policy and a deployment process for the first cloud computing component, wherein the instructions executable by the processor to cause the system to deploy the first cloud computing component comprise instructions executable by the processor to cause the system to deploy the first cloud computing component in accordance with the blueprint.
5 . (canceled)
6 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to periodically retrieve security compliance information from the agent.
7 . (canceled)
8 . A method comprising:
selecting a first security policy for a first cloud computing component, wherein the first security policy indicates a plurality of security requirements; deploying the first cloud computing component along with an agent to monitor whether the first cloud computing component complies with the plurality of security requirements; receiving first security compliance information from the agent; in response to a determination that the first security compliance information indicates that the deployed first cloud computing component does not comply with a first security requirement of the plurality of security requirements,
indicating that the first cloud computing component does not comply with the first security policy; and
modifying the deployed first cloud computing component to comply with the first security requirement;
receiving second security compliance information from the agent; and in response to a determination that the second security compliance information indicates that the deployed first cloud computing component complies with the plurality of security requirements, indicating that the first cloud computing complies with the first security policy.
9 . (canceled)
10 . The method of claim 8 further comprising:
selecting a cloud computing component template from a cloud computing component template catalog, wherein the cloud computing component template corresponds to the first cloud computing component;
wherein modifying the deployed first cloud computing component to comply with the first security requirement comprise modifying the cloud computing component template and redeploying the first cloud computing component in accordance with the modified cloud computing component template.
11 . The method of claim 8 further comprising creating a cloud computing application blueprint, wherein the blueprint comprises information regarding the first security policy and a deployment process for the first cloud computing component, wherein deploying the first cloud computing component comprises deploying the first cloud computing component in accordance with the blueprint.
12 . (canceled)
13 . The method of claim 8 further comprising periodically retrieving security compliance information from the agent.
14 . (canceled)
15 . A non-transitory computer readable storage medium with instructions stored thereon, the instructions to:
select a first security policy for a first cloud computing component, wherein the first security policy indicates a plurality of security requirements; deploy the first cloud computing component along with an agent to monitor whether the first cloud computing component complies with the plurality of security requirements; receive first security compliance information from the agent; and in response to a determination that the first security compliance information indicates that the deployed first cloud computing component does not comply with a first security requirement of the plurality of security requirements,
indicate that the first cloud computing component does not comply with the first security policy; and
modify the deployed first cloud computing component to comply with the first security requirement;
receive second security compliance information from the agent; and in response to a determination that the second security compliance information indicates that the deployed first cloud computing component complies with the plurality of security requirements, indicate that the first cloud computing component complies with the first security policy.
16 . (canceled)
17 . The non-transitory computer readable storage medium of claim 15 further comprising instructions to:
select a cloud computing component template from a cloud computing component template catalog, wherein the cloud computing component template corresponds to the first cloud computing component;
wherein the instructions to modify the deployed first cloud computing component to comply with the first security requirement comprise instructions to modify the cloud computing component template and redeploy the first cloud computing component in accordance with the modified cloud computing component template.
18 . The non-transitory computer readable storage medium of claim 15 further comprising instructions to a cloud computing application blueprint, wherein the blueprint comprises information regarding the first security policy and a deployment process for the first cloud computing component, wherein the instructions to deploy the first cloud computing component comprise instructions to deploy the first cloud computing component in accordance with the blueprint.
19 . (canceled)
20 . (canceled)
21 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to:
determine that a second security requirement of the plurality of security requirements indicates that data of the first cloud computing component should be password protected; deploy a second cloud computing component, wherein the second cloud computing component receives data from the first cloud computing component and is monitored by the agent; receive third security compliance information from the agent; and in response to a determination that the third security compliance information indicates that the deployed second cloud computing component does not comply with the second security requirement, modify the deployed second cloud computing component to provide password protection for data received from the first cloud computing component.
22 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to:
determine whether the deployed first cloud computing component complies with each of the plurality of security requirements based, at least in part, on actual use of the deployed first cloud computing component and planned use of the deployed first cloud computing component, wherein the actual use and the planned use is indicated in the first security compliance information; and generate a compliance report based, at least in part, on the determination of whether the deployed first cloud computing component compiles with each of the plurality of security requirements, wherein the compliance report indicates a compliance status of the deployed first cloud computing component.
23 . The system of claim 1 , wherein the computer readable storage medium further has instructions executable by the processor to cause the system to:
determine that the first security compliance information comprises an indication of a security event, wherein the security event was an attempt to violate security of the first cloud computing component; and in response to the indication of the security event, update the first cloud computing component with a second security policy, wherein the second security policy imposes greater security than the first security policy.
24 . The method of claim 8 further comprising:
determining that a second security requirement of the plurality of security requirements indicates that data of the first cloud computing component should be password protected;
deploying a second cloud computing component, wherein the second cloud computing component receives data from the first cloud computing component and is monitored by the agent;
receiving third security compliance information from the agent; and
in response to a determination that the third security compliance information indicates that the deployed second cloud computing component does not comply with the second security requirement, modifying the deployed second cloud computing component to provide password protection for data received from the first cloud computing component.
25 . The method of claim 8 further comprising:
determining whether the deployed first cloud computing component complies with each of the plurality of security requirements based, at least in part, on actual use of the deployed first cloud computing component and planned use of the deployed first cloud computing component, wherein the actual use and the planned use is indicated in the first security compliance information; and
generating a compliance report based, at least in part, on the determination of whether the deployed first cloud computing component compiles with each of the plurality of security requirements, wherein the compliance report indicates a compliance status of the deployed first cloud computing component.
26 . The method of claim 8 further comprising:
determining that the first security compliance information comprises an indication of a security event, wherein the security event was an attempt to violate security of the first cloud computing component; and
in response to the indication of the security event, updating the first cloud computing component with a second security policy, wherein the second security policy imposes greater security than the first security policy.
27 . The non-transitory computer readable storage medium of claim 15 further comprising instructions to:
determine that a second security requirement of the plurality of security requirements indicates that data of the first cloud computing component should be password protected;
deploy a second cloud computing component, wherein the second cloud computing component receives data from the first cloud computing component and is monitored by the agent;
receive third security compliance information from the agent; and
in response to a determination that the third security compliance information indicates that the deployed second cloud computing component does not comply with the second security requirement, modify the deployed second cloud computing component to provide password protection for data received from the first cloud computing component.
28 . The non-transitory computer readable storage medium of claim 15 further comprising instructions to:
determine whether the deployed first cloud computing component complies with each of the plurality of security requirements based, at least in part, on actual use of the deployed first cloud computing component and planned use of the deployed first cloud computing component, wherein the actual use and the planned use is indicated in the first security compliance information; and
generate a compliance report based, at least in part, on the determination of whether the deployed first cloud computing component compiles with each of the plurality of security requirements, wherein the compliance report indicates a compliance status of the deployed first cloud computing component.
29 . The non-transitory computer readable storage medium of claim 15 further comprising instructions to:
determine that the first security compliance information comprises an indication of a security event, wherein the security event was an attempt to violate security of the first cloud computing component; and
in response to the indication of the security event, update the first cloud computing component with a second security policy, wherein the second security policy imposes greater security than the first security policy.Join the waitlist — get patent alerts
Track US2016359911A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.