Providing security in a cloud storage environment
Abstract
A method of providing security as a service in a cloud storage environment includes storing, through a cloud manager of the cloud storage environment, a security level of access of a storage controller associated with a customer of the security as a service, and receiving a request from the customer to access security information of the storage controller associated therewith. The method also includes providing, through the cloud manager, security information of the storage controller associated with the customer in accordance with the request and the stored security level of access of the storage controller associated with the customer.
Claims
exact text as granted — not AI-modified1 - 28 . (canceled)
29 . A machine implemented method, comprising:
providing security as a service by a cloud manager in a cloud storage environment, where the cloud manager includes one or more computing devices; maintaining a data structure for tracking charges associated with transmitting to a customer of the security as a service, security information about a storage controller associated therewith in accordance with a security level of access provided thereto through the cloud manager; crediting an amount of money by the cloud manager, when security information transmitted to the customer fails to correspond to security information requested by the customer in accordance with the security level of access; and charging the customer the amount of money by the cloud manager when security information is requested in accordance with the security level of access and the security information is successfully transmitted to the customer.
30 . The method of claim 29 , wherein the security information about the storage controller associated with the customer includes at least one of information associated with authenticating the customer, attestation confirmation of a computing platform on which data associated with the customer is configured to be stored, signature data of the storage controller associated with the computing platform attestation and at least one parameter other than the signature data of the storage controller.
31 . The method of claim 29 , further comprising: providing at least one of network as a service, performance as a service, storage space as a service, cloud monitoring as a service, engineering support as a service, cloud auto-scaling as a service, and server utilization as a service to the customer, through the cloud manager, as part of a service agreement, in addition to the security service.
32 . The method of claim 31 , wherein information associated with authenticating the customer is obtained through one of a hardware based authentication scheme and a software based authentication scheme provided through a service provider.
33 . The method of claim 30 , wherein the signature data of the storage controller includes a list of hashes of at least one of a version of the BIOS on the storage controller, a storage operating system version executing on the storage controller, a physical hardware identification attribute of the storage controller and a configuration information associated with the storage controller.
34 . The method of claim 33 , wherein the hardware based authentication scheme includes:
registering the storage controller with an authentication server configured to be set up in the cloud storage environment; and authenticating the storage controller based on a communication protocol between a client device associated with the customer, the authentication server and the storage controller.
35 . A non-transitory, machine readable storage medium storing executable instructions, which when executed by a machine, causes the machine to perform a method, the method comprising:
providing security as a service by a cloud manager in a cloud storage environment, where the cloud manager includes one or more computing devices; maintaining a data structure for tracking charges associated with transmitting to a customer of the security as a service, security information about a storage controller associated therewith in accordance with a security level of access provided thereto through the cloud manager; crediting an amount of money by the cloud manager, when security information transmitted to the customer fails to correspond to security information requested by the customer in accordance with the security level of access; and charging the customer the amount of money by the cloud manager when security information is requested in accordance with the security level of access and the security information is successfully transmitted to the customer.
36 . The storage medium of claim 35 , wherein the security information about the storage controller associated with the customer includes at least one of information associated with authenticating the customer, attestation confirmation of a computing platform on which data associated with the customer is configured to be stored, signature data of the storage controller associated with the computing platform attestation and at least one parameter other than the signature data of the storage controller.
37 . The storage medium of claim 35 , the method further comprising: providing at least one of network as a service, performance as a service, storage space as a service, cloud monitoring as a service, engineering support as a service, cloud auto-scaling as a service, and server utilization as a service to the customer, through the cloud manager, as part of a service agreement, in addition to the security service.
38 . The storage medium of claim 37 , wherein information associated with authenticating the customer is obtained through one of a hardware based authentication scheme and a software based authentication scheme provided through a service provider.
39 . The storage medium of claim 36 , wherein the signature data of the storage controller includes a list of hashes of at least one of a version of the BIOS on the storage controller, a storage operating system version executing on the storage controller, a physical hardware identification attribute of the storage controller and a configuration information associated with the storage controller.
40 . The storage medium of claim 39 , wherein the hardware based authentication scheme includes registering the storage controller with an authentication server configured to be set up in the cloud storage environment; and authenticating the storage controller based on a communication protocol between a client device associated with the customer, the authentication server and the storage controller.
41 . A cloud storage environment, comprising:
a storage controller configured to host at least one server associated with a customer of a security as a service; and a processor executing instructions out of a memory for: maintaining a data structure for tracking charges associated with transmitting to a customer of the security as a service, security information about the storage controller associated therewith in accordance with a security level of access provided thereto; crediting an amount of money when security information transmitted to the customer fails to correspond to security information requested by the customer in accordance with the security level of access; and charging the customer the amount of money when security information is requested in accordance with the security level of access and the security information is successfully transmitted to the customer.
42 . The cloud storage environment of claim 41 , wherein the security information about the storage controller associated with the customer includes at least one of information associated with authenticating the customer, attestation confirmation of a computing platform on which data associated with the customer is configured to be stored, signature data of the storage controller associated with the computing platform attestation and at least one parameter other than the signature data of the storage controller.
43 . The cloud storage environment of claim 41 , a cloud manager providing at least one of network as a service, performance as a service, storage space as a service, cloud monitoring as a service, engineering support as a service, cloud auto-scaling as a service, and server utilization as a service to the customer, through the cloud manager, as part of a service agreement, in addition to the security service.
44 . The cloud storage environment of claim 43 , wherein information associated with authenticating the customer is obtained through one of a hardware based authentication scheme and a software based authentication scheme provided through a service provider.
45 . The cloud storage environment of claim 43 , wherein the signature data of the storage controller includes a list of hashes of at least one of a version of the BIOS on the storage controller, a storage operating system version executing on the storage controller, a physical hardware identification attribute of the storage controller and a configuration information associated with the storage controller.
46 . The cloud storage environment of claim 45 , wherein the hardware based authentication scheme includes registering the storage controller with an authentication server configured to be set up in the cloud storage environment; and authenticating the storage controller based on a communication protocol between a client device associated with the customer, the authentication server and the storage controller.Join the waitlist — get patent alerts
Track US2014137214A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.