Compute Appliance Reference State Compliance Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy server architectures face challenges in orchestrating control due to the separation of administrative control between physical and logical infrastructure, leading to security vulnerabilities from unauthorized modifications of compute and network infrastructure states, which are difficult to manage in large-scale cloud-based computing systems.

Innovation Solution

Implementing a pre-boot and runtime supervisory service within compute appliances to enforce compliance with reference compute and network infrastructure states by verifying complex IDs and configuration criteria, and taking remedial actions to prevent unauthorized changes, thereby ensuring secure operation within a cloud-based computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a cloud architecture uses multiple physical server nodes with software-defined logical infrastructure, then the system provides flexible service orchestration and abstraction, but security vulnerabilities arise from unauthorized modifications of compute and network infrastructure states

Engineering Contradiction:
Improveservice orchestration flexibilityVSAvoidinfrastructure state security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements pre-boot supervisory services that verify compute state compliance before the compute appliance joins the cloud system. This preliminary verification prevents unauthorized modifications by checking hardware configuration, firmware versions, and component integrity against reference states before allowing system access, thereby addressing security concerns while maintaining orchestration flexibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuous runtime supervisory services that monitor compute state changes and provide feedback to the central management system. When deviations from reference states are detected, the system automatically triggers compliance verification and remediation actions, creating a closed-loop feedback mechanism that maintains infrastructure security without compromising service orchestration capabilities

Inventive Principle:
Principle #23Feedback

2Reliability

If the system verifies compute state compliance for every compute appliance, then system security and integrity are improved, but the complexity of managing large-scale cloud systems increases

Engineering Contradiction:
Improvesystem integrityVSAvoidcompliance management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service compliance verification where compute appliances automatically perform pre-boot integrity checks and runtime self-monitoring of their own compute states. The supervisory services reside on each compute appliance and autonomously verify compliance against reference states, reducing the operational burden on central management systems while maintaining comprehensive system integrity across large-scale deployments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent divides compliance verification into segmented responsibilities: pre-boot verification handled by supervisory services on each compute appliance, runtime monitoring by dedicated supervisory processes, and central coordination by the management system. This segmentation distributes verification complexity across multiple levels, making large-scale compliance management tractable while ensuring thorough system integrity checking

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If unauthorized modifications are allowed to maintain system adaptability, then service flexibility is improved, but security vulnerabilities and system compromise increase

Engineering Contradiction:
Improveservice flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing pre-boot supervisory services that proactively verify compute state compliance before unauthorized modifications can occur. The system checks hardware configurations, firmware integrity, and component states against reference profiles during the boot process, preventing security vulnerabilities before they can compromise system adaptability or service flexibility

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11949583B2Enforcing reference operating state compliance for cloud computing-based compute appliances
Publication Date: 2024.04.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11949583B2 patent drawing
  • US11949583B2 patent drawing
  • US11949583B2 patent drawing

AI summary

A process includes enforcing compliance of a compute appliance to a reference operating state for the compute appliance. The compute appliance is part of a cloud-based computing system. Enforcing compliance with the reference operating state includes, responsive to a startup of the compute appliance, the compute appliance determining an actual compute state of the compute appliance. The actual compute state includes an actual physical topology placement of a hardware component of the compute appliance. Determining the actual compute state includes determining the physical topology placement of the hardware component. Enforcing compliance with the reference operating state includes verifying whether the actual compute state complies with the reference compute state. The verification includes comparing the actual compute state to the reference compute state. Enforcing compliance with the reference operating state includes, responsive to a result of the verification, controlling whether the compute appliance is part of the cloud-based computing system.