MODEL BASED SYSTEMS MANAGEMENT IN VIRTUALIZED AND NON-VIRTUALIZED ENVIRONMENTS
    1.
    发明申请
    MODEL BASED SYSTEMS MANAGEMENT IN VIRTUALIZED AND NON-VIRTUALIZED ENVIRONMENTS 有权
    虚拟化和非虚拟化环境中的基于模型的系统管理

    公开(公告)号:US20110138441A1

    公开(公告)日:2011-06-09

    申请号:US12633805

    申请日:2009-12-09

    摘要: Architecture that provides model-based systems management in virtualized and non-virtualized environments. A security component provides security models which define security requirements for services. A management component applies one or more of the security models during the lifecycle of virtual machines and services. The lifecycle can include initial deployment, expansion, moving servers, monitoring, and reporting. The architecture creates a formal description model of how a virtual machine or a service (composition of multiple virtual machines) is secured. The security requirements information can also be fed back to the general management system which uses this information in its own activities such as to guide the placement of workloads on servers can be security related.

    摘要翻译: 在虚拟化和非虚拟化环境中提供基于模型的系统管理的架构。 安全组件提供了定义服务安全性要求的安全模型。 管理组件在虚拟机和服务的生命周期中应用一个或多个安全模型。 生命周期可以包括初始部署,扩展,移动服务器,监控和报告。 该架构创建了如何保护虚拟机或服务(多个虚拟机的组合)的正式描述模型。 安全要求信息也可以反馈给在其自身活动中使用该信息的通用管理系统,以指导服务器上的工作负载的布置可以与安全相关。

    Automated security classification and propagation of virtualized and physical virtual machines
    2.
    发明授权
    Automated security classification and propagation of virtualized and physical virtual machines 有权
    虚拟化和物理虚拟机的自动安全分类和传播

    公开(公告)号:US08799985B2

    公开(公告)日:2014-08-05

    申请号:US12727267

    申请日:2010-03-19

    IPC分类号: H04L29/06 G06F21/53

    CPC分类号: G06F21/53 H04L63/20

    摘要: Architecture that provides additional data that can be obtained and employed in security models in order to provide security to services over the service lifecycle. The architecture automatically propagates security classifications throughout the lifecycle of the service, which can include initial deployment, expansion, moving servers, monitoring, and reporting, for example, and further include classification propagation from the workload (computer), classification propagation in the model, classification propagation according to the lineage of the storage location (e.g., virtual hard drive), status propagation in the model and classification based on data stored in the machine.

    摘要翻译: 提供可在安全模型中获取和使用的附加数据的架构,以便在服务生命周期中为服务提供安全性。 该架构在服务的整个生命周期中自动传播安全性分类,其可以包括初始部署,扩展,移动服务器,监视和报告,并且还包括来自工作负载(计算机)的分类传播,模型中的分类传播, 根据存储位置(例如,虚拟硬盘驱动器)的沿袭分类传播,模型中的状态传播和基于存储在机器中的数据的分类。

    AUTOMATED SECURITY CLASSIFICATION AND PROPAGATION OF VIRTUALIZED AND PHYSICAL VIRTUAL MACHINES
    3.
    发明申请
    AUTOMATED SECURITY CLASSIFICATION AND PROPAGATION OF VIRTUALIZED AND PHYSICAL VIRTUAL MACHINES 有权
    虚拟化和物理虚拟机的自动安全分类和传播

    公开(公告)号:US20110138442A1

    公开(公告)日:2011-06-09

    申请号:US12727267

    申请日:2010-03-19

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53 H04L63/20

    摘要: Architecture that provides additional data that can be obtained and employed in security models in order to provide security to services over the service lifecycle. The architecture automatically propagates security classifications throughout the lifecycle of the service, which can include initial deployment, expansion, moving servers, monitoring, and reporting, for example, and further include classification propagation from the workload (computer), classification propagation in the model, classification propagation according to the lineage of the storage location (e.g., virtual hard drive), status propagation in the model and classification based on data stored in the machine.

    摘要翻译: 提供可在安全模型中获取和使用的附加数据的架构,以便在服务生命周期中为服务提供安全性。 该架构在服务的整个生命周期中自动传播安全性分类,其可以包括初始部署,扩展,移动服务器,监视和报告,并且进一步包括来自工作负载(计算机)的分类传播,模型中的分类传播, 根据存储位置(例如,虚拟硬盘驱动器)的沿袭分类传播,模型中的状态传播和基于存储在机器中的数据的分类。

    Policy-management infrastructure
    4.
    发明授权
    Policy-management infrastructure 有权
    政策管理基础设施

    公开(公告)号:US08307404B2

    公开(公告)日:2012-11-06

    申请号:US11735800

    申请日:2007-04-16

    IPC分类号: G06F17/00

    CPC分类号: G06Q10/06

    摘要: Described herein are one or more implementations of a policy-management infrastructure that provides a universal policy-based solution across a spectrum of scenarios in a computing environment. At least one implementation of the policy-management infrastructure defines how policy-based data is structured or layered relative towards the data in other layers. Furthermore, a described implementation provides a mechanism for determining “overlap” and “conflicts” in policies.

    摘要翻译: 这里描述了策略管理基础设施的一个或多个实现,其在计算环境中的一系列场景下提供基于策略的通用解决方案。 政策管理基础设施的至少一个实施方案定义了基于策略的数据如何相对于其他层中的数据进行结构化或分层化。 此外,所描述的实现提供了用于确定策略中的重叠和冲突的机制。

    Policy-Management Infrastructure
    5.
    发明申请
    Policy-Management Infrastructure 有权
    政策管理基础设施

    公开(公告)号:US20080256593A1

    公开(公告)日:2008-10-16

    申请号:US11735800

    申请日:2007-04-16

    IPC分类号: G06F17/00

    CPC分类号: G06Q10/06

    摘要: Described herein are one or more implementations of a policy-management infrastructure that provides a universal policy-based solution across a spectrum of scenarios in a computing environment. At least one implementation of the policy-management infrastructure defines how policy-based data is structured or layered relative towards the data in other layers. Furthermore, a described implementation provides a mechanism for determining “overlap” and “conflicts” in policies.

    摘要翻译: 这里描述了策略管理基础设施的一个或多个实现,其在计算环境中的一系列场景下提供基于策略的通用解决方案。 政策管理基础设施的至少一个实施方案定义了基于策略的数据如何相对于其他层中的数据进行结构化或分层化。 此外,所描述的实现提供了一种用于确定策略中的“重叠”和“冲突”的机制。

    Highly available large scale network and internet systems
    6.
    发明授权
    Highly available large scale network and internet systems 有权
    高可用的大型网络和互联网系统

    公开(公告)号:US08495557B2

    公开(公告)日:2013-07-23

    申请号:US12061668

    申请日:2008-04-03

    IPC分类号: G06F17/30 G06F12/00

    CPC分类号: G06F17/30

    摘要: Described is a technology by which a system corresponding to a large scale application is built from subsystems that are differentiated from one another based on characteristics of each subsystem. Example characteristics include availability, reliability, redundancy, statefulness and/or performance. Subsystems are matched to known design patterns, based on each subsystem's individual characteristics. Each subsystem's characteristics are associated with that subsystem for subsequent use in operation of the system, e.g., for managing/servicing the subsystem. The known design patterns may be provided in a library, in a programming framework, in conjunction with a development tool, and/or as data associated with one or more operating system services, server systems and/or hosted services that include at least one configuration, policy and or schema. Certain design patterns and/or characteristics patterns may be blocked to prevent their usage.

    摘要翻译: 描述了一种基于每个子系统的特征,从与彼此不同的子系统构建与大规模应用相对应的系统的技术。 示例特性包括可用性,可靠性,冗余性,状态性和/或性能。 基于每个子系统的各个特征,子系统与已知的设计模式相匹配。 每个子系统的特征与该子系统相关联,用于随后在系统的操作中使用,例如用于管理/维护子系统。 已知的设计模式可以在库,编程框架中与开发工具一起提供,和/或作为与一个或多个操作系统服务,服务器系统和/或托管服务相关联的数据提供,其包括至少一个配置 ,策略和/或模式。 某些设计模式和/或特征模式可能被阻止以防止其使用。

    Method and system for retrieval of stored graphs
    9.
    发明授权
    Method and system for retrieval of stored graphs 失效
    存储图形检索方法和系统

    公开(公告)号:US4852019A

    公开(公告)日:1989-07-25

    申请号:US825081

    申请日:1986-01-31

    IPC分类号: G06T1/00 G06F17/30

    CPC分类号: G06F17/30265

    摘要: Automation of retrieval of stored graphs in a multi-user system having a central processing facility with processes that create and translate graphical representation into varying levels of readable expression. The created, translated representations are stored in system storage in the form of graph files. The invention is expressed as a method that tabularizes stored graph files by table entries, each identifying a specific graph and including a listing of the corresponding graph files produced for the graph. When a user of the system identifies a graph by table entry and specifies a machine output or modification function to be performed on the identified graph, the tabularized entries are searched to locate an entry for the identified graph. Once the correct table entry is found, the graph file listing is searched according to a user-specified representation preference ordering in the form of a priority schedule to determine whether a specified output function can be performed with any of the stored graph files stored for the identified graph. If a match is found between one of the representations stored for the graph and one of the representations in the priority schedule, the matched file is retrieved from storage and translated to the level required for the function. The translated file is then dispatched to a graphical output device for performance of the function.

    摘要翻译: 在具有中央处理设施的多用户系统中检索存储的图形的自动化,其具有创建和将图形表示转换成不同级别的可读表达式的过程。 创建的,翻译的表示以图形文件的形式存储在系统存储器中。 本发明表示为通过表格表格化存储的图形文件的方法,每个表格标识特定图形并且包括为图形生成的对应的图形文件的列表。 当系统的用户通过表条目识别图形并指定要在识别的图形上执行的机器输出或修改功能时,搜索表格化的条目以找到用于所识别的图形的条目。 一旦找到了正确的表格条目,就可以根据用户指定的表示优先级排序以优先级调度的形式搜索图形文件列表,以确定是否可以对任何存储的图形文件执行指定的输出功能, 识别图。 如果在为图表存储的一个表示和优先级调度中的一个表示之间找到匹配,则从存储中检索匹配的文件并将其转换为该功能所需的级别。 然后将转换的文件分派到图形输出设备以执行该功能。