Centralized Cloud Administration Engine for Multi-Datacenter Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud platforms face challenges in managing administration tasks across multiple data centers, as malicious actors can exploit these tasks to cause significant damage, and conventional methods require expertise in specific cloud platforms, leading to inefficiencies and security risks.

Innovation Solution

A cloud platform-independent declarative specification is used to generate and manage data centers, allowing for portable administration operations across various cloud platforms, with a domain-specific language that compiles platform-specific instructions, and a centralized administration engine and agents to manage administration operations securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud platforms provide scalability and elasticity of computing resources, then productivity and adaptability are improved, but security risks and administration task management complexity increase

Engineering Contradiction:
Improvescalability and elasticity of computing resourcesVSAvoidsecurity risks of administration tasks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a cloud platform as an intermediary layer between traditional data centers and service providers. This intermediary provides standardized administration tasks that mediate between the scalability benefits of cloud platforms and the security requirements of administration, allowing secure management of cloud resources through defined interfaces and protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If organizations maintain data centers on cloud platforms using continuous delivery platforms, then ease of operation and scalability are improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvecontinuous delivery and deploymentVSAvoidcloud infrastructure management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates universal administration tasks that can be performed across multiple cloud platforms using standardized interfaces. These tasks serve multiple functions: they provide platform-agnostic access to cloud resources, enable consistent administration across different clouds, and simplify operations by using common protocols rather than platform-specific tools

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a multi-tenant system manages services for a large number of organizations, then adaptability and service coverage are improved, but device complexity and security surface area increase

Engineering Contradiction:
Improvemulti-tenant service managementVSAvoidadministration task management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments administration tasks into discrete, standardized units that can be independently managed and assigned to different tenants. This segmentation allows the system to manage multiple tenants through a unified framework while maintaining clear boundaries and access controls for each tenant's specific administration needs

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11870860B2Administration of services executing in cloud platform based datacenters
Publication Date: 2024.01.09 SALESFORCE INC
  • US11870860B2 patent drawing
  • US11870860B2 patent drawing
  • US11870860B2 patent drawing

AI summary

A cloud infrastructure is configured and deployed for managing services executed on a cloud platform. The cloud infrastructure includes a control datacenter configured to communicate with one or more service datacenters. The service datacenter deploys one or more application programming interfaces (API's) associated with a service. The service datacenter also deploys an administration agent. The control datacenter hosts an engine that receives requests from users to perform administration operations by invoking the administration API's. In this manner, the control datacenter functions as a centralized control mechanism that effectively distributes administration operation requests as they are received from users to service datacenters that can service the requests. The cloud infrastructure provides an auditable, compliant and secure management system for administering services for distributed systems running in the cloud.