Dynamic Route Adjustment for Policy Compliance in Cloud Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based multi-tenant systems face challenges in managing data residency and routing policies across distributed cloud networks, particularly in ensuring compliance with varying security regulations and residency requirements across different countries.
Innovation Solution
A cloud-based multi-tenant system that employs policy-driven locality and residency management by determining and distributing routes characterized by locality and residency, allowing applications to select policies and receive corresponding routes for secure and compliant communication with cloud services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS is used to provide predetermined path routing, then routing control and QoS management are improved, but routing flexibility and adaptability to dynamic policies deteriorate
Solution Approach 1:
The patent implements dynamic route selection by allowing applications to request specific routes based on changing policies. The system transitions from static MPLS paths to dynamic routing decisions where routes can be adjusted in real-time based on policy changes, residency requirements, and network conditions. This enables the system to adapt routing paths dynamically while maintaining control.
Solution Approach 2:
The system changes routing parameters by allowing policy-driven modifications to route characteristics. Applications can specify different route parameters (such as latency, bandwidth, or residency location) and the system adjusts routing parameters accordingly. This enables flexible adaptation to different policy requirements while maintaining reliable routing control through parameter optimization.
2Reliability
If data flows are regulated with global cloud traffic controller, then security and compliance are improved, but system complexity and operational overhead worsen
Solution Approach 1:
The patent introduces a route manager as an intermediary component that handles policy translation and route selection. This mediator sits between applications and the global cloud traffic controller, translating high-level policy requirements into specific routing decisions. This reduces the complexity burden on applications while maintaining security and compliance through centralized regulation.
Solution Approach 2:
Applications are enabled to self-select routes based on their policy requirements without requiring complex configuration from network administrators. The system provides self-service route selection where applications can specify their needs (such as residency or latency requirements) and automatically receive appropriate routing configurations, reducing operational overhead while maintaining security compliance.
3Reliability
If multiple routes are provided for different policies, then policy compliance and data residency control are improved, but routing decision complexity and processing time worsen
Solution Approach 1:
The system performs preliminary actions by pre-configuring and pre-calculating valid routes based on policy requirements. Routes are prepared in advance with their compliance characteristics documented, allowing rapid selection when policy changes occur. This preliminary preparation reduces the time needed for routing decisions while ensuring policy compliance through pre-validated route configurations.
Solution Approach 2:
The system implements feedback mechanisms where route performance and compliance status are continuously monitored. This feedback information is used to optimize future routing decisions, allowing the system to learn from past performance and make faster, more accurate route selections. The feedback loop enables rapid decision-making by eliminating invalid routes based on real-time compliance status and performance data.
Data Source
AI summary
A method and system for mediating non-compliance of residency policies associated with multiple routes within a cloud-based multi-tenant system. The system includes several routes for delivering services to various end user devices, with each route connecting to different cloud services across the Internet. A telemetry beacon is deployed to monitor compliance with pre-configured residency, routing, and performance settings, which link to multiple residency policies of the routes. An application running on an end user device requests a residency policy from the available residency policies, where residency policies control residency requirements for cloud services and routes. The telemetry beacon transmits compliance data related to the selected residency policy to an Application Resource Server (ARS). The ARS detects non-compliance with the residency policy based on this telemetry data and updates the route to resolve the issue. The system uses the updated route to facilitate communication between the application and the cloud service.


