Security policy enforcement framework for cloud-based information processing systems
    1.
    发明授权
    Security policy enforcement framework for cloud-based information processing systems 有权
    基于云的信息处理系统的安全策略实施框架

    公开(公告)号:US08689282B1

    公开(公告)日:2014-04-01

    申请号:US13336692

    申请日:2011-12-23

    IPC分类号: H04L29/06

    CPC分类号: H04L63/20

    摘要: Cloud infrastructure of a cloud service provider comprises a processing platform implementing a security policy enforcement framework. The security policy enforcement framework comprises a policy analyzer that is configured to identify at least one security policy associated with at least one tenant of the cloud service provider, to analyze the security policy against configuration information characterizing the cloud infrastructure of the cloud service provider, and to control execution of one or more applications of said at least one tenant within the cloud infrastructure in accordance with the security policy, based at least in part on one or more results of the analysis of the security policy. The security policy enforcement framework may be implemented in a platform-as-a-service (PaaS) layer of the cloud infrastructure, and may comprise a runtime controller, an operating system controller, a hypervisor controller and a PaaS controller.

    摘要翻译: 云服务提供商的云基础设施包括实施安全策略实施框架的处理平台。 安全策略实施框架包括策略分析器,其被配置为识别与云服务提供商的至少一个租户相关联的至少一个安全策略,以针对表征云服务提供商的云基础设施的配置信息来分析安全策略;以及 至少部分地基于对安全策略的分析的一个或多个结果来根据安全策略来控制云基础设施内的所述至少一个租户的一个或多个应用的​​执行。 安全策略实施框架可以在云基础架构的平台即服务(PaaS)层中实现,并且可以包括运行时控制器,操作系统控制器,管理程序控制器和PaaS控制器。

    Secure tenant assessment of information technology infrastructure
    5.
    发明授权
    Secure tenant assessment of information technology infrastructure 有权
    信息技术基础设施安全租户评估

    公开(公告)号:US08782795B1

    公开(公告)日:2014-07-15

    申请号:US13436020

    申请日:2012-03-30

    IPC分类号: H04L29/06

    CPC分类号: H04L63/205 H04L63/1433

    摘要: Information technology infrastructure comprises a computing environment shared by multiple tenants of a service provider, and a secure assessment environment separate from the shared computing environment. An evidence collection module associated with the shared computing environment collects compliance evidence from the shared computing environment for storage in the secure assessment environment. A tenant assessment interface to the secure assessment environment is provided, through which the tenants can access the compliance evidence as stored in the secure assessment environment in a manner that does not undermine security of the shared computing environment. The compliance evidence may include, for example, information sufficient to allow a tenant to verify that the shared computing environment is configured in accordance with a specified security policy. In an illustrative embodiment, the information technology infrastructure comprises cloud infrastructure of a cloud service provider and the shared computing environment comprises a cloud computing environment.

    摘要翻译: 信息技术基础设施包括由服务提供商的多个租户共享的计算环境,以及与共享计算环境分离的安全评估环境。 与共享计算环境相关联的证据收集模块从共享计算环境收集合规性证据,以便在安全评估环境中进行存储。 提供了对安全评估环境的租户评估界面,租户可以以不破坏共享计算环境安全性的方式访问存储在安全评估环境中的合规证据。 合规证据可以包括例如足以允许租户根据指定的安全策略来验证共享计算环境被配置的信息。 在说明性实施例中,信息技术基础设施包括云服务提供商的云基础设施,共享计算环境包括云计算环境。

    Verification of controls in information technology infrastructure via obligation assertion
    8.
    发明授权
    Verification of controls in information technology infrastructure via obligation assertion 有权
    通过义务言论验证信息技术基础设施的控制

    公开(公告)号:US09043793B1

    公开(公告)日:2015-05-26

    申请号:US13075639

    申请日:2011-03-30

    摘要: A processing device comprises a processor coupled to a memory and implements an obligation management system for information technology infrastructure, with the obligation management system being configured to process a plurality of obligations on behalf of a relying party to verify implementation of corresponding controls in information technology infrastructure of a claimant. A given one of the obligations has an associated obligation fulfiller that is inserted or otherwise deployed as a component within the information technology infrastructure of the claimant and is configured to provide evidence of the implementation of one or more of the controls responsive to an obligation assertion so as to establish an associated trust aspect of the claimant. The information technology infrastructure may comprise distributed virtual infrastructure of a cloud service provider. The claimant may comprise the cloud service provider and the relying party may comprise a tenant of the cloud service provider.

    摘要翻译: 处理设备包括处理器,其耦合到存储器并且实现用于信息技术基础设施的义务管理系统,其中义务管理系统被配置为代表依赖方处理多个义务以验证信息技术基础设施中相应控制的实现 的索赔人。 给定的一项义务有一个相关的义务履行者被插入或以其他方式部署在索赔人的信息技术基础设施内的组成部分,并且被配置为提供响应于义务声明的一个或多个控制的执行的证据 以建立索赔人的相关信托方面。 信息技术基础设施可以包括云服务提供商的分布式虚拟基础设施。 索赔人可以包括云服务提供商,并且依赖方可以包括云服务提供商的租户。