Cloud Platform Network System for Secure Multi-Tenant Application Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud platforms face challenges in maintaining high security and cost-efficiency while managing applications across diverse computing environments and devices, as enterprises need to manage various contexts and devices with different operating systems and software environments, requiring a solution for secure and efficient application and policy management.

Innovation Solution

A network system with an application management module, community management module, and user enrollment portal that decouples client device administration, allowing multiple communities and applications to be managed separately, enabling secure access and policy enforcement across various devices and computing environments, with a cloud-based management framework that supports independent container management and unified user interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud platforms manage applications across diverse computing environments and devices, then versatility and adaptability are improved, but device complexity and management difficulty increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the cloud platform into distinct functional modules: an application management module for deploying and managing applications, a community management module for organizing users and devices, and a user enrollment portal for onboarding. This modular segmentation allows each component to handle specific aspects of diversity independently, improving adaptability while containing complexity within manageable modules rather than having a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including computing environment agents installed on client devices that act as local intermediaries between the diverse device environments and the centralized cloud platform. These agents translate and standardize device-specific information into a unified format that the cloud platform can process, enabling the system to handle diverse computing environments without directly managing each device's complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud platforms provide secure access across multiple devices and computing environments, then reliability is improved, but device complexity and management overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy management mechanism that operates across all computing environments and devices through the community management module. This universal approach defines policies at the community level that automatically apply to all members regardless of their specific device or computing environment, ensuring consistent security and reliability without requiring device-specific management configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The computing environment agents serve as intermediaries that enforce security policies locally on diverse devices while reporting to the centralized cloud platform. This intermediary layer ensures reliable security enforcement across multiple devices without requiring the cloud platform to directly manage each device's security configuration, thereby maintaining security while reducing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If enterprises manage various contexts and devices with different operating systems and software environments, then adaptability is improved, but loss of time and management efficiency worsen

Engineering Contradiction:
ImproveadaptabilityVSAvoidtime
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action through the user enrollment portal and community management module, which pre-configure computing environments, assign policies, and deploy applications before users need them. The system proactively manages device onboarding, software environment setup, and application deployment in advance, eliminating the need for time-consuming manual configuration when users need to access services across different devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The computing environment agents enable self-service functionality by automatically detecting the device's computing environment, retrieving appropriate applications and policies from the cloud platform, and configuring the local environment without manual intervention. This self-service capability allows users to quickly access services on new devices without requiring time-consuming IT management assistance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9571564B2Network system for implementing a cloud platform
Publication Date: 2017.02.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9571564B2 patent drawing
  • US9571564B2 patent drawing
  • US9571564B2 patent drawing

AI summary

A network system for implementing a cloud platform within a network to which at least one device defining a computing environment for a user has access comprises an application management module, a community management module, and a user enrollment portal. The application management module enables access to an abstract application, wherein the abstract application is associated with a concrete application defining an implementation of the abstract application for the computing environment. The community management module manages a community, wherein the community comprised of at least a user credential and the abstract application, wherein the community defines at least one of said following: a policy, a management process, and a service, under which the abstract application can be accessed by the user. The user enrollment portal supports an enrollment of the user in the community from the device, and to orchestrate a policy management mechanism to support an enforcement of the policy under which the user has access to the concrete application from the device.