US 12,231,468 B2
LCS resource policy enforcement system
Douglas Lang Farley, Round Rock, TX (US); Ethan A. Kaley, North Kingstown, RI (US); Judith Furlong, Natick, MA (US); Geoffrey A. Reid, Littleton, MA (US); John Harwood, Boston, MA (US); and Gaurav Chawla, Austin, TX (US)
Assigned to Dell Products L.P., Round Rock, TX (US)
Filed by Dell Products L.P., Round Rock, TX (US)
Filed on Jul. 15, 2022, as Appl. No. 17/866,351.
Prior Publication US 2024/0022605 A1, Jan. 18, 2024
Int. Cl. G06F 15/16 (2006.01); H04L 9/40 (2022.01); H04L 47/80 (2022.01)
CPC H04L 63/20 (2013.01) [H04L 47/80 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A Logically Composed System (LCS) resource policy enforcement system, comprising:
a plurality of resource devices;
a Logically Composed System (LCS) provisioning administrator device that is coupled to the plurality of resource devices;
a first client system; and
an orchestrator device that is coupled to the plurality of resource devices and the first client system, wherein the orchestrator device is configured to:
provide, to the first client system using a first subset of the plurality of resource devices and based on a workload intent provided by the first client system, a first LCS;
associate the first LCS with a first client identifier for the first client system;
tag, with the first client identifier, each of the first subset of the plurality of resource devices being used to provide the first LCS;
identify at least one first LCS policy for the first LCS; and
apply the at least one first LCS policy to each of the first subset of the plurality of resource devices tagged with the first client identifier to cause the at least one first LCS policy to be enforced on the first client system and the LCS provisioning administrator device, wherein the enforcement of the at least one first LCS policy on the first client system and the LCS provisioning administrator device includes:
allowing a first subsystem in the first client system to access client data that is generated by the first LCS at the instruction of the first subsystem during the provisioning of the first LCS; and
preventing the LCS provisioning administrator device from accessing the client data.