Dynamic VM Grouping via Expression Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing workload grouping techniques in virtualized datacenters are restrictive and non-intuitive, leading to inefficient resource sharing and virtualization, as they are based on physical or compute-centric buckets rather than dynamic networking and security requirements.

Innovation Solution

A dynamic expression evaluation module groups VM objects based on user-defined expressions combining VM attributes and identity attributes, creating security groups to provide networking and security services, using set theory to translate VM objects into entities like IP and MAC addresses for enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If workload grouping is based on physical or compute-centric buckets (resource pools, datacenters, clusters), then networking and security services can be provided, but resource sharing and virtualization efficiency deteriorate

Engineering Contradiction:
Improvenetworking and security service provisionVSAvoidresource sharing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic workload grouping that automatically adjusts group assignments based on current networking and security requirements rather than static physical locations. The system continuously evaluates workload attributes and reassigns workloads to appropriate security groups dynamically, enabling efficient resource sharing while maintaining reliable security service provision.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the virtualized datacenter into logical security groups based on networking and security requirements rather than physical infrastructure. This segmentation allows workloads with similar security needs to be grouped together regardless of their physical location, improving resource utilization while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

2Reliability

If workload grouping is based on physical or compute-centric buckets, then networking and security services can be provided, but the grouping becomes restrictive and non-intuitive

Engineering Contradiction:
Improvenetworking and security service provisionVSAvoidgrouping intuitiveness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides an intuitive, dynamic interface for defining security groups based on workload attributes and requirements rather than fixed physical structures. Administrators can create flexible grouping rules that automatically adapt to changing workload characteristics, making the system both intuitive to operate and reliable for security service provision.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a virtualization management system that acts as an intermediary between physical infrastructure and security requirements. This intermediary layer translates high-level security policies into actionable group assignments, making the system intuitive to operate while maintaining reliable security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If workloads are categorized in physical clusters or resource pools, then networking and security services can be delivered, but adaptability to different networking and security requirements deteriorates

Engineering Contradiction:
Improvenetworking and security service deliveryVSAvoidadaptability to networking and security requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security group assignments that automatically adapt to changing networking and security requirements. The system continuously evaluates workload attributes and reassigns workloads to appropriate security groups based on current requirements, maintaining reliable service delivery while providing high adaptability to different scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the grouping parameters from fixed physical locations to dynamic security attributes. By evaluating workload attributes and requirements in real-time, the system can adapt security group assignments to match changing networking and security needs while maintaining reliable service delivery.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9420004B2Dynamic expression evaluation based grouping of VM objects for networking and security services in a virtualized computing system
Publication Date: 2016.08.16 VMWARE INC
  • US9420004B2 patent drawing
  • US9420004B2 patent drawing
  • US9420004B2 patent drawing

AI summary

Techniques for grouping virtual machine (VM) objects for networking and security services in a virtualized computing system are described. In one example embodiment, VM attributes and identity attributes are obtained from a virtual center and an identity server, respectively. One or more desired security groups are then formed based on security requirements of the virtualized computing system. A user defined dynamic expression is then associated with the one or more security groups. One or more expression attributes are then determined by evaluating the user defined dynamic expression using the obtained VM attributes and identity attributes. VM objects are then grouped based on the determined one or more expression attributes. The grouped VM objects are then associated with the created one or more security groups for providing the networking and security services.