Declarative Policy Management for Cloud Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-defined data centers face challenges in automating policy management across multiple cloud services due to heterogeneity in resources and infrastructure silos, making it difficult to enforce policies proactively and reactively, especially when real-world policies are written in high-level terms and span multiple infrastructure components.

Innovation Solution

A system that uses a declarative policy language to integrate with cloud service management data, converting data from various sources into a unified format, and enforces policies proactively, reactively, and interactively through a user interface, allowing administrators to select corrective actions, with a compiler converting policies into database operations to manage policy violations across compute, networking, and storage resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unified policy management system is implemented across multiple cloud services, then policy enforcement capability is improved, but system complexity increases due to heterogeneity of resources and infrastructure silos

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy management system as an intermediary layer between cloud service providers and cloud consumers. This mediator translates high-level policy requirements into service-specific enforcement actions, handling the heterogeneity of different cloud services (compute, storage, networking) without requiring direct integration with each service's underlying infrastructure, thus improving policy enforcement while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The policy management system is segmented into distinct functional modules: policy definition interface, policy translation engine, policy enforcement interface, and monitoring components. Each module handles specific aspects of policy management independently, allowing the system to manage complexity through modular design while maintaining comprehensive policy enforcement across multiple cloud services.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If policies are written in high-level terms (users, applications, data), then ease of policy definition is improved, but difficulty in mapping to actual cloud resources (compute, networking, storage) increases

Engineering Contradiction:
Improveease of policy definitionVSAvoiddifficulty in mapping to cloud resources
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The policy translation engine acts as an intermediary that automatically maps high-level policy terms (users, applications, data) to underlying cloud resource identifiers (compute instances, storage volumes, network configurations). This translation layer shields policy writers from complexity while ensuring accurate resource mapping through automated resolution of abstract terms to concrete resource references.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal policy language that can express policies in terms of abstract concepts (users, applications, data) while simultaneously supporting mapping to diverse cloud resource types (compute, storage, networking). This multi-functional policy language allows the same high-level policy syntax to work across different cloud service domains without requiring service-specific policy definitions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If proactive policy enforcement is implemented to prevent violations, then compliance level is improved, but automation complexity increases

Engineering Contradiction:
Improvecompliance levelVSAvoidautomation complexity
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The policy enforcement interface proactively evaluates proposed cloud resource actions before they are executed. By performing preliminary policy checks on intended actions (such as resource provisioning or configuration changes), the system prevents policy violations before they occur, improving compliance while automating the evaluation process through rule-based enforcement logic that reduces manual intervention complexity.

Inventive Principle:
Principle #10Preliminary action

4Ease of manufacture

If piecemeal solutions focused on individual cloud services (compute, networking, storage) are used, then ease of implementation is improved, but ability to enforce policies spanning multiple infrastructure silos deteriorates

Engineering Contradiction:
Improveease of implementationVSAvoidability to enforce cross-service policies
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal policy enforcement framework that can handle policies spanning multiple cloud service types (compute, storage, networking) through a single integrated system. The framework maintains service-specific enforcement capabilities while providing cross-service policy coordination, allowing organizations to implement comprehensive multi-service policies without requiring separate piecemeal solutions for each infrastructure silo.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11343159B2Policy declarations for cloud management system
Publication Date: 2022.05.24 VMWARE INC
  • US11343159B2 patent drawing
  • US11343159B2 patent drawing
  • US11343159B2 patent drawing

AI summary

Methods, apparatus, systems and articles of manufacture are disclosed related to policy declarations for cloud management system. An example computer readable storage device includes instructions that, when executed, cause processor circuitry to at least identify a proposed change to a state of a network. The example instructions, when executed, also cause the processor circuitry to, in response to identifying the proposed change, determine whether the proposed change will cause the state of the network to violate a policy, the policy including a query plan describing characteristics to evaluate the proposed change. In some examples, the instructions, when executed, cause the processor circuitry to, when the proposed change will cause the state of the network to violate the policy, execute an application programming interface call to a cloud service provider to cause the cloud service provider to prevent violation of the policy by executing an action associated with the proposed change.