Secured logical component for security in a virtual environment

US9584544B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9584544-B2
Application numberUS-201313795275-A
CountryUS
Kind codeB2
Filing dateMar 12, 2013
Priority dateMar 12, 2013
Publication dateFeb 28, 2017
Grant dateFeb 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for providing security in a virtual environment are provided. An example system includes a link module that links a secured logical component to a logical entity including a set of virtual machines. The example system also includes a security module that identifies a set of security policies for one or more communications to the logical entity or one or more communications from the logical entity. The example system further includes a control module that controls, based on the set of security policies, the one or more communications to the logical entity or the one or more communications from the logical entity.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for providing security in a virtualization environment, the system comprising: a link module that links a first secured logical component to a first logical entity including a first set of virtual machines, wherein the first secured logical component includes a network interface, and the link module links a logical network associated with the first logical entity to the network interface, links the first secured logical component to a second logical entity including a second set of virtual machines, and links the logical network associated with the second logical entity to the network interface, wherein the second logical entity is associated with a first set of host machines running the second set of virtual machines, wherein the first set of host machines includes a first set of physical network interfaces, and each virtual machine of the second set of virtual machines includes one or more first virtual network interfaces associated with the first set of physical network interfaces, and wherein the link module links the one or more first virtual network interfaces of the second set of virtual machines to the logical network, wherein the first logical entity is associated with a second set of host machines running the first set of virtual machines, wherein the second set of host machines includes a second set of physical network interfaces, and each virtual machine of the first set of virtual machines includes one or more second virtual network interfaces associated with the second set of physical network interfaces, wherein the link module links the one or more second virtual network interfaces of the first set of virtual machines to the logical network; a security module that identifies a set of security policies for one or more communications to the first logical entity or one or more communications from the first logical entity and that identifies a set of security policies for one or more communications between the first logical entity and the second logical entity; and a control module that controls, based on the set of security policies, the one or more communications to the first logical entity or the one or more communications from the first logical entity and that controls, based on the set of security the one or more communications between the first logical entity and the second logical entity, wherein the first secured logical component includes the link module, security module, and control module, wherein the first secured logical component runs on a virtual machine running on a host machine of the first set of host machines and receives communications via a physical network interface of the first set of physical network interfaces, wherein the virtual machine is migrated to a host machine of the second set of host machines, and after migration, the virtual machine receives communications via a physical network interface of the second set of physical network interfaces. 2. The system of claim 1 , wherein the first secured logical component runs on a preconfigured virtual machine running on a host machine. 3. The system of claim 2 , wherein the preconfigured virtual machine is preconfigured to run an operating system without user selection of the operating system. 4. The system of claim 1 , wherein the link module unlinks the first secured logical component from the second logical entity and links the first secured logical component to a third logical entity including a third set of virtual machines, wherein the security module identifies a second set of security policies for one or more communications between the first logical entity and the third logical entity, and wherein the control module controls, based on the second set of security policies, one or more communications between the first logical entity and the third logical entity. 5. The system of claim 4 , wherein the link module links the logical network associated with the third logical entity to the network interface, wherein the third logical entity is associated with a third set of host machines running the third set of virtual machines, wherein the third set of host machines includes a third set of physical network interfaces, and each virtual machine of the third set of virtual machines includes a third virtual network interface associated with the third set of physical network interfaces, and wherein the link module links the one or more third virtual network interfaces of the third set of virtual machines to the logical network. 6. The system of claim 1 , wherein the link module links the first secured logical component to a network, the security module identifies the set of security policies for one or more communications received via the network to the first logical entity or one or more communications sent via the network from the first logical entity, and the control module controls based on the set of security policies the one or more communications received via the network to the first logical entity or the one or more communications sent via the network from the first logical entity. 7. The system of claim 1 , wherein the first logical entity is a first datacenter, the first secured logical component includes the link module, security module, and control module, and the link module links the first secured logical component to the second logical entity that is a second datacenter including the second set of virtual machines, wherein a second secured logical component is linked to the second datacenter, and the first and second secured logical components establish a secure connection and encrypt one or more communications between the first and second logical entities. 8. The system of claim 1 , wherein the first logical entity is at least one of a datacenter, cluster, and virtual machine. 9. A method of providing security in a virtualization environment, the method comprising: linking, at a virtual machine running on a host machine, a first secured logical component to a first logical entity including a first set of virtual machines; identifying a network interface of the first secured logical component; linking a logical network associated with the first logical entity to the network interface; linking the first secured logical component to a second logical entity including a second set of virtual machines; linking the logical network associated with the second logical entity to the network interface; identifying, at the virtual machine, a set of security policies for one or more communications between the first logical entity and the second logical entity; identifying a first set of host machines associated with the second logical entity, the first set of host machines running the second set of virtual machines and including a first set of physical network interfaces; identifying one or more virtual network interfaces associated with the second set of virtual machines and the first set of physical network interfaces; linking the one or more virtual network interfaces of the second set of virtual machines to the logical network; identifying a second set of host machines associated with the first logical entity, the second set of host machines running the first set of virtual machines and including a second set of physical network interfaces; identifying one or more virtual network interfaces associated with the first set of virtual machines and the second set of physical network interfaces; and linking the one or more virtual network interfaces of the first set of virtual machines to the logical network; and controlling, based on the set of security policies, the one or more communications between the first logical entity and the second logical entity, wherein the first secured logical component runs on a virtual machine runnin

Assignees

Inventors

Classifications

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • involving long-term monitoring or reporting · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9584544B2 cover?
A system and method for providing security in a virtual environment are provided. An example system includes a link module that links a secured logical component to a logical entity including a set of virtual machines. The example system also includes a security module that identifies a set of security policies for one or more communications to the logical entity or one or more communications f…
Who is the assignee on this patent?
Red Hat Israel Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).