Cloud Resource Discovery via Automated Service Account Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing and discovering computing resources across multiple projects in cloud-based networks due to the manual creation of service accounts, which is time-consuming and cumbersome, especially in dynamic environments where hundreds or thousands of accounts may need to be created.

Innovation Solution

A discovery computing system that automatically generates and manages service accounts across multiple projects by using APIs to retrieve organization and project information, allowing for the automatic discovery and mapping of computing resources, thereby reducing the need for manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If service accounts are created manually for each project in cloud-based networks, then the discovery computing system can discover and map computing resources, but the process becomes time-consuming and cumbersome, especially when hundreds or thousands of accounts need to be created

Engineering Contradiction:
Improvediscovery accuracyVSAvoidaccount creation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The discovery computing system automatically creates service accounts for projects using the organization's service account credentials, eliminating the need for manual account creation. The system self-services by programmatically generating service accounts through API calls, thereby resolving the contradiction between discovery accuracy and account creation time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by first obtaining organization service account credentials, then using these credentials to automatically create service accounts for multiple projects before resource discovery begins. This preliminary automated account creation resolves the time-consuming issue while maintaining discovery precision.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If service accounts are created manually for each project, then security credentials can be properly managed, but the complexity and effort required to manage multiple projects increases significantly

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The discovery computing system uses a universal organization service account that can access and create service accounts across multiple projects. This multi-functional approach maintains security credentials management while reducing system management complexity, as one organization-level account handles authentication for numerous projects.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the service account management by creating individual service accounts for each project while centralizing the creation process through the organization's service account. This segmentation maintains security isolation per project while simplifying overall management through automated centralized account creation.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated service account creation is implemented, then time and effort are reduced, but the system complexity increases due to API integration requirements

Engineering Contradiction:
Improveaccount creation efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The organization's service account acts as an intermediary that enables automated service account creation across multiple projects. This intermediary approach increases productivity by automating account creation while managing system architecture complexity through a standardized API-based mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12143268B2Automatic discovery of cloud-based infrastructure and resources
Publication Date: 2024.11.12 SERVICENOW INC
  • US12143268B2 patent drawing
  • US12143268B2 patent drawing
  • US12143268B2 patent drawing

AI summary

An embodiment may involve receiving an account identifier, wherein the account identifier is associated with a service account; transmitting a first API query to a remote computing system based on the account identifier; receiving first information associated with a first resource based on the first API query, wherein the first resource corresponds to a cloud orchestrator associated with a first service provided by the remote computing system; transmitting a first set of queries to the remote computing system based on the first information; receiving second information about a cluster of resources, associated with the first resource, based on the first set of queries, wherein a set of services related to the first service are deployed in one or more resources of the cluster of resources; generating a relationship map between the first resource and the cluster of resources based on the second information; and outputting the relationship map.