Cloud Identity Integration for On-Premises Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based data center management systems face challenges with one-way communication channels hindered by firewalls, proxies, and complex network setups, necessitating an always-connected, bidirectional connection to manage data center assets securely in real-time.

Innovation Solution

A method and system for performing a connectivity management operation involving exchanging entity tokens for proxy and device access tokens via a communication management system authorization service, authenticating services, establishing secure communication channels, and validating data center assets to enable end-to-end secure connections for data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-based management systems use traditional one-way communication channels, then network security is maintained through firewalls and proxies, but real-time bidirectional communication and management capability are blocked

Engineering Contradiction:
Improvereal-time management capabilityVSAvoidnetwork setup complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a mesh service proxy as an intermediary component that enables bidirectional communication between cloud-based management services and on-premises data center assets. The proxy acts as a mediator that traverses firewalls and complex network setups, allowing real-time communication without requiring direct connectivity or compromising network security. This resolves the contradiction by providing a simplified intermediary layer that enables complex bidirectional communication through otherwise blocking network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access tokens are exchanged and validated through multiple services, then authentication security is improved, but communication overhead and connection establishment time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing mesh service proxies on on-premises networks before actual management operations begin. These proxies are pre-configured with authentication credentials and network routing information, allowing them to immediately facilitate secure bidirectional communication when needed. The preliminary setup includes pre-validating authentication tokens and establishing trust relationships, so that when real-time management operations start, the system can skip repetitive authentication steps and directly establish data exchange channels, significantly reducing connection establishment time while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11843604B2Cloud identity integration for cloud-based management of on-premises devices
Publication Date: 2023.12.12 DELL PROD LP
  • US11843604B2 patent drawing
  • US11843604B2 patent drawing
  • US11843604B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a data center connectivity management operation. The connectivity management operation includes: exchanging an entity token for a proxy access token and a device access token via a communication management system authorization service; using the proxy access token to authenticate the data center service to a mesh service proxy; establishing connectivity between the data center service and the mesh service proxy based upon the proxy access token; establishing a secure communication channel between the data center service and a data center asset based upon the device access token; providing the device access token to the data center asset from the data center service; validating the data center asset using the device access token; establishing an end-to-end secure connection between the data center service and the data center asset when the device access token has been validated; and, exchanging information between the data center service and the data center asset via the secure communication channel.