CIM Opaque Management Data Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network management systems face challenges in efficiently modeling and managing opaque data, particularly in ensuring security and authenticity during remote management operations across diverse systems, leading to potential security breaches and scalability issues.
Innovation Solution
The implementation of a system and method using Distributed Management Task Force (DMTF) management profiles based on the Common Information Model (CIM) protocol, incorporating Role Based Authorization (RBA) and Simple Identity Management (SIM) profiles to authenticate access and manage quota-related operations, utilizing the CIM_Identity class, CIM_Role class, and CIM_Privilege class for secure and scalable opaque management data operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional network management systems perform remote management operations across diverse systems, then management functionality is provided, but security breaches and scalability issues occur
Solution Approach 1:
The patent introduces a management information service that acts as an intermediary between management devices and diverse network devices. This service provides a standardized interface using Common Information Model (CIM) classes to abstract the complexity of diverse systems, enabling secure and scalable management operations without direct exposure of underlying system variations.
Solution Approach 2:
The patent segments management operations into distinct functional components: authentication services, authorization services, and data management services. Each component operates independently with defined interfaces, improving scalability and security by isolating potential vulnerability points while maintaining overall system functionality.
2Ease of operation
If opaque management data is modeled without standardized authentication mechanisms, then data access is simplified, but security and authenticity cannot be ensured
Solution Approach 1:
The patent implements preliminary authentication and authorization actions before data access is permitted. Users must authenticate their identity and receive authorization tokens prior to accessing opaque management data. This preliminary verification ensures security and authenticity while maintaining ease of operation through automated token-based access mechanisms.
Solution Approach 2:
An authentication service and authorization service act as intermediaries between users and opaque management data. These services verify user identities, manage access rights, and issue tokens that enable data access without exposing authentication complexity to the data consumers, thus ensuring security while maintaining operational simplicity.
3Measurement precision
If storage variations are not abstracted in opaque management data, then data representation is accurate, but system scalability is compromised
Solution Approach 1:
The management information service acts as an intermediary layer that abstracts storage variations into standardized CIM classes. Different storage implementations are mapped to common data models, enabling accurate representation of storage characteristics while maintaining scalability through standardized interfaces that can accommodate various storage systems without requiring changes to management applications.
Solution Approach 2:
The patent creates universal data models using Common Information Model (CIM) classes that can represent multiple types of storage systems through a single standardized interface. This multi-functionality allows the system to scale by accommodating diverse storage implementations while maintaining data representation accuracy through the universal CIM framework.
Data Source
AI summary
Distributed Management Task Force (DMTF) management profiles, based on the Common Information Model (CIM) protocol, may be utilized to perform access authentication during opaque management data profile operations based on DMTF/CIM Role Based Authorization (RBA) profile and/or Simple Identity Management (SIM) profiles. Instances of CIM_Identity class may be utilized to enable validation of ownership and/or access rights, via instances of CIM_Role class and/or instances of CIM_Privilege class for a plurality of common users and/or applications. Quota related operations may be performed via “QuotaAffectsElement” associations between instances of CIM_Identity class and instances of the CIM_OpaqueManagementDataService class. The “QuotaAffectsElement” association may comprise “AllocationQuota” and/or “AllocatedBytes” properties to enable tracking and/or validating of quota related information within the opaque management data profile.


