Decentralized Configuration Management Using Virtual Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network service architectures, managing multiple system configuration data models across distributed environments is complex and insecure, leading to increased operational costs due to resource-intensive central configuration generation and potential security vulnerabilities.

Innovation Solution

A system that utilizes a local management server and configuration engine to generate and manage application-specific configuration data using standardized JSON objects, offloading configuration generation tasks from remote controllers to local entities, and employing virtual containers for secure data processing and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized configuration generation is used, then configuration management can be performed, but system complexity and operational costs increase dramatically

Engineering Contradiction:
Improveconfiguration managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent divides the centralized configuration management system into distributed configuration agents deployed across multiple network elements. Each agent independently manages configuration data locally, segmenting the monolithic centralized system into smaller autonomous units that reduce overall system complexity while maintaining configuration management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by implementing configuration management across the network dimension rather than through a single centralized point. Configuration agents are distributed across multiple network elements, transforming the management architecture from vertical centralization to horizontal distribution, thereby reducing operational costs and complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If centralized configuration generation is used, then configuration management can be performed, but processing requirements and operational costs increase

Engineering Contradiction:
Improveconfiguration managementVSAvoidprocessing requirements
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent enables configuration agents to autonomously generate and manage configuration data locally at each network element without requiring intensive centralized processing. Each agent self-services by maintaining local configuration databases and generating configuration parameters independently, significantly reducing the processing requirements and energy consumption of the overall system.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If distributed network service environment is used, then service scalability can be improved, but security issues increase

Engineering Contradiction:
Improveservice scalabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements local quality control by enabling each configuration agent to independently validate and secure its local configuration data. Security policies and validation rules are applied locally at each network element rather than centrally, allowing distributed scalability while maintaining consistent security standards across all nodes through localized enforcement.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If multiple system configuration data models are managed, then application specificity can be achieved, but maintenance complexity increases

Engineering Contradiction:
Improveapplication specificityVSAvoidmaintenance
Core Design Contradiction:
Adaptability or versatilityVSEase of repair

Solution Approach 1:

The patent implements a universal configuration data model that can represent multiple application-specific configuration types through a common structured format. The unified data model uses standardized parameters and data structures that can accommodate firewall rules, routing configurations, and other application-specific settings, thereby reducing maintenance complexity while preserving application specificity through configurable parameters.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11537409B2System and method for managing system configuration data models
Publication Date: 2022.12.27 FORCEPOINT LLC
  • US11537409B2 patent drawing
  • US11537409B2 patent drawing
  • US11537409B2 patent drawing

AI summary

A system, for managing application specific configuration data, that receives, from a local server, a standardized configuration object, at a configuration engine, for a configurable entity, generates at least one configuration object file for the configuration entity, wherein the standardized configuration object is generated based on the application specific configuration data according to a system wide metadata specification. The system can further write each configuration object file to a shared memory structure associated with a configuration file of a configurable entity. The system receives the configuration object, compares the configuration object with another standardized configuration object, and interfaces the configuration object with the configuration engine. The interfaced configuration object can be a piece of configuration. The system permits read access to the configuration engine to the configuration object, permits read and write access to the management server to the configuration object. The local management server executes in a virtual container.