Invention Grant
- Patent Title: Elastic enforcement layer for cloud security using SDN
- Patent Title (中): 使用SDN的云安全弹性执行层
-
Application No.: US13494637Application Date: 2012-06-12
-
Publication No.: US09304801B2Publication Date: 2016-04-05
- Inventor: Tommy Koorevaar , Makan Pourzandi , Ying Zhang
- Applicant: Tommy Koorevaar , Makan Pourzandi , Ying Zhang
- Applicant Address: SE Stockholm
- Assignee: Telefonaktiebolaget L M Erricsson (publ)
- Current Assignee: Telefonaktiebolaget L M Erricsson (publ)
- Current Assignee Address: SE Stockholm
- Agency: Nicholson, De Vos, Webster & Elliot, LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F9/455 ; H04L29/06 ; H04L12/725

Abstract:
An efficient elastic enforcement layer (EEL) for realizing security policies is deployed in a cloud computing environment based on a split architecture framework. The split architecture network includes a controller coupled to switches. When the controller receives a packet originating from a source VM, it extracts an application identifier from the received packet that identifies an application running on the source VM. Based on the application identifier, the controller determines a chain of middlebox types. The controller further determines middlebox instances based on current availability of resources. The controller then adds a set of rules to the switches to cause the switches to forward the packet toward the destination VM via the middlebox instances.
Public/Granted literature
- US20130332983A1 Elastic Enforcement Layer for Cloud Security Using SDN Public/Granted day:2013-12-12
Information query