Dynamic Policy Enforcement for Bound Services in Distributed Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional server management policies struggle to implement fine-grained, abstract, and natural rules due to their reliance on low-level constructs like IP addresses, making it difficult to manage servers with bound services having different high-level characteristics.

Innovation Solution

A method and system that generate management instructions for managed servers within an administrative domain using a set of rules, where information about changes in bound services is received, an updated description is generated, and relevant rules are determined to configure the server for enforcing function-level instructions based on the changed service characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If blanket rules are applied to all services on a device, then policy simplicity is maintained, but the ability to accommodate devices serving multiple functions is compromised

Engineering Contradiction:
Improveability to accommodate devices serving multiple functionsVSAvoidpolicy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments services into bound services and unbound services, allowing different policy treatments for each type. Bound services (with fixed host-port mappings) receive one set of rules while unbound services (dynamic port assignments) receive another, enabling fine-grained control without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by distinguishing between different service types on the same device and applying appropriate policies to each. The system recognizes that bound services have stable characteristics while unbound services are dynamic, and tailors policy responses accordingly for each service type

Inventive Principle:
Principle #3Local quality

2Ease of operation

If low-level constructs like IP addresses are used in policies, then precise control is achieved, but the ability to write fine-grained policies in an abstract and natural way is compromised

Engineering Contradiction:
Improveease of writing policiesVSAvoidpolicy precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces service type classification as an intermediary layer between high-level policy statements and low-level network controls. By categorizing services as bound or unbound, the system translates abstract policy intentions into precise technical implementations without requiring administrators to work with raw IP addresses and port numbers

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10693718B2Updating management instructions for bound services in a distributed network management system
Publication Date: 2020.06.23 ILLUMIO INC
  • US10693718B2 patent drawing
  • US10693718B2 patent drawing
  • US10693718B2 patent drawing

AI summary

Management instructions for a managed servers are updated according to a set of rules included in management policy. A global manager computer receives information describing a change in a bound service executed by the particular managed server. The global manager generates an updated description of the particular managed server is generated by modifying an initial description of the particular managed server according to the received information describing the change in the bound service. The global manager determines currently relevant rules for the particular managed server. If the currently-relevant rules differ from previously-relevant rules, the global manager determines a rule is that should be added. The global manager generates a function-level instruction including a reference to an authorized actor-set of actors permitted to communicate with the bound service. The global manager configures the particular managed server to enforce the function-level instruction.