CIM Opaque Management Data Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network management systems face challenges in efficiently modeling and managing opaque data, particularly in ensuring security and authenticity during remote management operations across diverse systems, leading to potential security breaches and scalability issues.

Innovation Solution

The implementation of a system and method using Distributed Management Task Force (DMTF) management profiles based on the Common Information Model (CIM) protocol, incorporating Role Based Authorization (RBA) and Simple Identity Management (SIM) profiles to authenticate access and manage quota-related operations, utilizing the CIM_Identity class, CIM_Role class, and CIM_Privilege class for secure and scalable opaque management data operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional network management systems perform remote management operations across diverse systems, then management functionality is provided, but security breaches and scalability issues occur

Engineering Contradiction:
Improvemanagement functionality across diverse systemsVSAvoidsecurity and scalability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a management information service that acts as an intermediary between management devices and diverse network devices. This service provides a standardized interface using Common Information Model (CIM) classes to abstract the complexity of diverse systems, enabling secure and scalable management operations without direct exposure of underlying system variations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments management operations into distinct functional components: authentication services, authorization services, and data management services. Each component operates independently with defined interfaces, improving scalability and security by isolating potential vulnerability points while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If opaque management data is modeled without standardized authentication mechanisms, then data access is simplified, but security and authenticity cannot be ensured

Engineering Contradiction:
Improvedata accessVSAvoidsecurity and authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before data access is permitted. Users must authenticate their identity and receive authorization tokens prior to accessing opaque management data. This preliminary verification ensures security and authenticity while maintaining ease of operation through automated token-based access mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication service and authorization service act as intermediaries between users and opaque management data. These services verify user identities, manage access rights, and issue tokens that enable data access without exposing authentication complexity to the data consumers, thus ensuring security while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If storage variations are not abstracted in opaque management data, then data representation is accurate, but system scalability is compromised

Engineering Contradiction:
Improvedata representation accuracyVSAvoidsystem scalability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The management information service acts as an intermediary layer that abstracts storage variations into standardized CIM classes. Different storage implementations are mapped to common data models, enabling accurate representation of storage characteristics while maintaining scalability through standardized interfaces that can accommodate various storage systems without requiring changes to management applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates universal data models using Common Information Model (CIM) classes that can represent multiple types of storage systems through a single standardized interface. This multi-functionality allows the system to scale by accommodating diverse storage implementations while maintaining data representation accuracy through the universal CIM framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8745701B2Method and system for modeling options for opaque management data for a user and/or an owner
Publication Date: 2014.06.03 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8745701B2 patent drawing
  • US8745701B2 patent drawing
  • US8745701B2 patent drawing

AI summary

Distributed Management Task Force (DMTF) management profiles, based on the Common Information Model (CIM) protocol, may be utilized to perform access authentication during opaque management data profile operations based on DMTF/CIM Role Based Authorization (RBA) profile and/or Simple Identity Management (SIM) profiles. Instances of CIM_Identity class may be utilized to enable validation of ownership and/or access rights, via instances of CIM_Role class and/or instances of CIM_Privilege class for a plurality of common users and/or applications. Quota related operations may be performed via “QuotaAffectsElement” associations between instances of CIM_Identity class and instances of the CIM_OpaqueManagementDataService class. The “QuotaAffectsElement” association may comprise “AllocationQuota” and/or “AllocatedBytes” properties to enable tracking and/or validating of quota related information within the opaque management data profile.