Distributed Indexing Engine Policy Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management tools in distributed computing systems face inefficiencies in translating policies for virtual objects to low-level identities, leading to time-consuming and unnecessary database queries due to multiple calls and combined results from various translation components.

Innovation Solution

A distributed indexing engine is used by a network management server to translate policies for virtual objects into identity information, such as IP addresses and logical port addresses, by forming an object graph and distributing rules to hosts for controlling network traffic between computing devices and virtual objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple translation components are used to translate policies for different object types, then comprehensive policy translation coverage is achieved, but translation time and database query overhead increase significantly

Engineering Contradiction:
Improvepolicy translation coverageVSAvoidtranslation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges multiple separate translation components into a single unified translation component that handles all object types (virtual machines, containers, applications, etc.). This unified component maintains comprehensive policy translation coverage while eliminating the overhead of coordinating multiple separate components and their individual database queries, thus resolving the contradiction between versatility and translation time.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The translation component is designed with multi-functionality to translate policies for diverse object types including virtual machines, containers, applications, and other runtime objects. By making the translation component universal rather than specialized for single object types, the system achieves comprehensive coverage without the time penalty of multiple specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple translation components query databases separately and combine results, then complete translation results are obtained, but database query overhead and system complexity increase

Engineering Contradiction:
Improvetranslation result completenessVSAvoidtranslation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate translation components and their individual database query operations into a single unified translation component. This unified component retrieves all necessary translation data through a single database query process, ensuring complete translation results while dramatically reducing system complexity by eliminating the need to coordinate multiple separate components and their result combination logic.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the coordination overhead and result combination logic from the translation process. By using a unified translation component, the system eliminates the complex orchestration required to manage multiple separate components, their individual database queries, and the merging of their results, thereby reducing system complexity while maintaining result completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12021898B2Processes and systems that translate policies in a distributed computing system using a distributed indexing engine
Publication Date: 2024.06.25 VMWARE INC
  • US12021898B2 patent drawing
  • US12021898B2 patent drawing
  • US12021898B2 patent drawing

AI summary

This disclosure presents processes and systems that translate policies defined for virtual objects, such as virtual servers, applications, and databases, of a distributed computing system into identity information of services provided by virtual objects to computing devices located outside the distributed computing system. Processes and systems form object graphs of computing device identity information, virtual objects, and virtual object identify information. Processes and systems translate polices for controlling network between the computing devices and the virtual objects into identity information of the computing devices and the virtual objects. The identify information of the virtual objects and the computing devices is used to create rules for controlling network traffic between the virtual objects and the computing devices. The rules are distributed to hosts of the distributed computing system that execute the rules, allowing access by the computing devices to services provided by the virtual objects.