Access Control for Data Processing Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized IT infrastructures, managing access to resources during high workloads and fluctuations is challenging, leading to potential overload and inefficient resource allocation, where heterogeneous services with different priorities compete for scarce resources, resulting in increased opportunity costs and potential service level agreement violations.
Innovation Solution
A method and control program that optimize resource allocation by formulating an integer program to prioritize service requests based on their priority metrics and opportunity costs, considering continuous demand and resource occupancy coefficients, and using heuristics to recalculate shadow prices and available capacities dynamically, ensuring efficient resource utilization and proactive rejection of low-priority services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If resources are shared among heterogeneous services with different priorities, then resource utilization efficiency is improved, but service level agreement compliance deteriorates under high workload
Solution Approach 1:
The patent applies local quality by differentiating resource allocation policies for different service classes based on their priority and SLA requirements. High-priority services receive guaranteed resource quotas and preferential treatment during overload conditions, while low-priority services are subject to throttling or rejection. This localized differentiation resolves the contradiction by ensuring SLA compliance for critical services while maintaining overall resource utilization efficiency through flexible allocation to non-critical services.
Solution Approach 2:
The system dynamically changes allocation parameters such as resource quotas, priority weights, and admission thresholds based on current workload conditions and service priorities. During high workload periods, the system adjusts these parameters to prioritize SLA-compliant services, while during low utilization periods, it optimizes for overall resource efficiency. This dynamic parameter adjustment resolves the contradiction between maintaining SLA compliance and maximizing resource utilization.
2Reliability
If access control is implemented to prioritize high-priority services, then service level agreement compliance is improved, but resource allocation flexibility deteriorates
Solution Approach 1:
The patent implements dynamic access control where resource allocation policies are not fixed but adapt in real-time based on workload conditions, service priorities, and available capacity. The system continuously monitors resource utilization and adjusts admission decisions, quota allocations, and priority weights dynamically. This dynamic approach resolves the contradiction by maintaining SLA compliance through adaptive prioritization while preserving allocation flexibility through real-time policy adjustment based on system state.
Solution Approach 2:
The system incorporates feedback mechanisms that monitor service performance, resource utilization, and SLA compliance metrics, then use this information to adjust access control decisions and resource allocation policies. The feedback loop enables the system to learn from past performance and optimize allocation strategies, resolving the contradiction between rigid SLA enforcement and flexible resource management by continuously adapting to actual system conditions and performance outcomes.
3Reliability
If resource quotas are strictly enforced for each service, then service level agreement compliance is improved, but overall system productivity deteriorates
Solution Approach 1:
The patent merges strict quota enforcement for high-priority services with flexible resource sharing for low-priority services. Rather than applying uniform strict quotas to all services, the system combines guaranteed minimum allocations for SLA-critical services with opportunistic resource sharing for non-critical services. This hybrid approach resolves the contradiction by ensuring SLA compliance for essential services while maintaining overall system productivity through efficient utilization of remaining capacity by other services.
Solution Approach 2:
The system applies partial strictness to resource quota enforcement based on service priority levels. For high-priority services with strict SLA requirements, near-strict quota enforcement is applied. For lower-priority services, more flexible quota management with over-subscription capabilities is used. This graduated approach to quota enforcement resolves the contradiction by applying strictness only where necessary for SLA compliance while maintaining productivity through flexible resource sharing elsewhere in the system.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
In order to control access to resources of a data processing system, a priority code is determined for an access request to at least one resource. A comparison code for granting access to the at least one requested resource is determined concerning an alternative use of the resource. For a totality of resource requests to the data processing system, an extreme value for a sum is determined via products of a corresponding priority code and of a number of resource accesses which can be granted in each case, taking into account a maximum capability of a requested resource. For a resource request, it is checked whether the priority code and the comparison code show a predetermined mutual relation. Access is granted depending on the extreme value determined and on the result of the check.