Publication Number

US-7823185-B1

Patent

Publication Date

2010-10-26

Expiration Date

2025-06-08


Abstract

A system, method, and computer program product for increasing security of grid enabled computing environments. The system, method, and computer program product include: scheduling execution of a computing job; determining if an edge policy exists for the computing job; tracking said execution of the computing job; dividing the computing job into portions; assigning the portions of the computing job according to the edge policy; determining if there is an attempt to violate the edge policy; and prohibiting a violation of the edge policy.

Core Innovation

The invention provides a system, method, and computer program product for increasing security in grid enabled computing environments by implementing an edge management system. This system manages the execution of computing jobs by scheduling them, determining if an edge policy exists, tracking their execution, dividing the job into portions, assigning those portions based on the edge policy, monitoring for policy violations, and prohibiting any violations. The edge policy is a set of rules that determine how and where a computing job is permitted to execute across different computing environments, ensuring security constraints are met.

The problem being addressed arises from conventional grid schedulers that lack sufficient security features to prevent grid jobs from running on nodes that do not meet the required security levels. As grids expand beyond local clusters to more global environments, the risk of sensitive data being processed on unsecured nodes increases. Existing schedulers rely mainly on their own security settings and lack mechanisms to override scheduling policies that might inadvertently schedule jobs on less secure nodes. This deficiency limits the expansion of true grid computing and risks insufficient enforcement of corporate or application-level security policies in distributed computing environments.

The invention provides a comprehensive edge manager that establishes corporate level security policies to override scheduler decisions, ensuring that jobs are only executed on nodes that comply with established edge policies. This manager tracks execution, communicates with nodes and their schedulers, transmits agents to enforce policies, and can prohibit violations by commanding nodes to cease processing or preventing data transmission. The edge management system can operate within a single computing environment or across complex networks, including the global Internet, corporate networks, subnets, clusters, and servers.

Claims Coverage

The patent includes six independent claims covering a method, system, computer, computer program product, and apparatus for edge management in grid computing environments, highlighting key inventive features related to policy enforcement and scheduling control.

Edge policy-based scheduling and enforcement

A method scheduling execution of a computing job while storing an edge policy that governs execution. The method tracks execution, divides the job into portions, assigns these portions to computers according to the edge policy, and communicates with the assigned computers' schedulers to enforce the policy and prevent passing the job to unauthorized computers.

System with integrated edge manager and schedulers

A system including a computing environment with a scheduler and an edge manager configured to determine and enforce an edge policy during job execution, assign job portions accordingly, communicate with schedulers on nodes, and prevent nodes' schedulers from transferring jobs to unauthorized nodes.

Computer configured for edge management

A computer with a scheduler and processor-equipped edge manager that determines and enforces edge policies, partitions jobs, assigns job portions to compliant nodes, communicates with their schedulers, and restricts unauthorized job transfers between nodes.

Computer program product encoding the edge management method

A non-transitory computer readable medium with instructions causing a computer system to perform the edge management method involving policy determination, job partitioning, assignment according to policies, communication with schedulers, enforcement of policies, and prevention of unauthorized job transfers.

Means-plus-function apparatus for edge management

An apparatus comprising means for scheduling, storing edge policies, tracking execution, dividing jobs, assigning job portions based on policies, communicating with scheduler components, enforcing edge policies and preventing noncompliant job transfers.

Agent-based policy enforcement

Use of agents transmitted to nodes and their schedulers, acting as daemon processes, APIs, or software modules that gather node information, relay it to the edge manager, and enable the node's scheduler to enforce the edge policy, with continued monitoring through job completion.

The claims collectively cover the implementation of an edge management system that schedules and assigns grid computing jobs in compliance with stored edge policies, communicates with node schedulers, utilizes agents to enforce these policies, and prevents the execution of jobs on non-compliant nodes, thereby securing grid environments across diverse network boundaries.

Stated Advantages

Increases security of grid enabled computing environments by enforcing strict edge policies that prevent execution of jobs on insufficiently secure nodes.

Allows expansion from quasi-grid cluster computing to true grid computing by managing security across multiple clusters and networks.

Provides a corporate-level override of individual scheduler policies to ensure consistent enforcement of security policies.

Enables more efficient use of existing computing resources by securely distributing jobs across multiple processors, potentially reducing costs and increasing processing speed.

Supports monitoring and real-time prohibition of policy violations via commands or data transmission controls.

Employs hierarchical and weighted policy definitions to handle overlapping edge policies effectively.

Documented Applications

Management and security enforcement of grid enabled computing jobs within single clusters, multiple clusters, corporate networks, and global Internet environments.

Securely paralleling computing jobs outside of an organization's internal grid onto external nodes such as university networks or individual computers on the Internet.

Controlling distributed application routing and grid resource identification in environments with multiple, diverse schedulers.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.