Hierarchical API for Multi-Segmented Application Manifests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current micro-segmentation approaches in enterprise data centers are cumbersome and not scalable, requiring manual management of grouping criteria and error-prone application discovery, especially in dynamic environments with ephemeral workloads, and lack efficient mechanisms for fine-grained control of firewall rules.

Innovation Solution

The introduction of application-based manifests that define and modify application segments and their communication profiles, using a hierarchical API processed by a manifest-processing framework to automate the deployment and configuration of network and service rules in a software-defined datacenter, enabling endpoint and network attribute-based micro-segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual management of grouping criteria is used for micro-segmentation, then fine-grained control of firewall rules can be achieved, but administrative overhead increases and scalability deteriorates

Engineering Contradiction:
Improvefine-grained controlVSAvoidadministrative overhead
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables self-service through automated application discovery and classification. The classification engine automatically discovers applications, extracts attributes, and creates segmentation rules without requiring manual administrator intervention for each rule, thereby reducing administrative overhead while maintaining fine-grained control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary classification engine that acts as a mediator between application workloads and firewall rule management. This engine automatically discovers applications, extracts attributes, and generates segmentation policies, eliminating the need for manual management while preserving detailed control capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual application discovery and classification is performed, then security policies can be created, but time consumption increases and error-proneness worsens

Engineering Contradiction:
Improvepolicy accuracyVSAvoiddiscovery and classification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The classification engine performs preliminary automated discovery and classification of applications before security policies need to be created. By pre-extracting application attributes and pre-establishing segmentation groups, the system eliminates time-consuming manual discovery while ensuring accurate, consistent policy creation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical classification processes with an automated classification engine that uses attribute extraction and analysis. This substitution eliminates human error-proneness and significantly reduces the time required for application discovery and classification while improving policy accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If traditional micro-segmentation approaches are used, then firewall rules can be enforced, but scalability deteriorates in dynamic workload environments

Engineering Contradiction:
Improvefirewall rule enforcementVSAvoidscalability in dynamic environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic adaptability by continuously monitoring workload attributes and automatically adjusting segmentation rules. The classification engine can dynamically discover new applications, update attributes, and modify security policies in real-time, enabling scalable enforcement in dynamic container and virtualized environments without sacrificing rule reliability

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10628144B2Hierarchical API for defining a multi-segmented application in an SDDC
Publication Date: 2020.04.21 VMWARE INC
  • US10628144B2 patent drawing
  • US10628144B2 patent drawing
  • US10628144B2 patent drawing

AI summary

Some embodiments provide a simplified mechanism to deploy and control a multi-segmented application by using application-based manifests that express how application segments of the multi-segment application are to be defined or modified, and how the communication profiles between these segments. In some embodiments, these manifests are application specific. Also, in some embodiments, deployment managers in a software defined datacenter (SDDC) provide these manifests as templates to administrators, who can use these templates to express their intent when they are deploying multi-segment applications in the datacenter. Application-based manifests can also be used to control previously deployed multi-segmented applications in the SDDC. Using such manifests would enable the administrators to be able to manage fine grained micro-segmentation rules based on endpoint and network attributes.