Map Server Zero-Touch Service Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network configurations require pre-known locations and IP/subnet addresses for cloud-based and on-premises applications and services, leading to costly and time-consuming network reconfigurations and potential security lapses during deployment, especially in critical operations.
Innovation Solution
The implementation of a fabric network with a Map Server (MS) that dynamically detects and registers the locations and subnets of applications, services, and servers, allowing for zero-touch deployment and policy-controlled traffic management without pre-configured network changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-known locations and IP/subnet addresses are required for network configuration, then network security and control are improved, but deployment time and complexity increase
Solution Approach 1:
The Map Server performs preliminary actions by proactively discovering and registering service locations, subnets, and addresses before actual service deployment. Border devices pre-register their capabilities and policies with the Map Server, enabling the network to be ready to accept services immediately without waiting for manual configuration of each service's network parameters.
Solution Approach 2:
The system enables self-service through automated service registration and location discovery. When a service is deployed, it automatically registers with the Map Server which then autonomously discovers its location, determines its subnet, and configures routing policies without requiring manual intervention. This self-configuration maintains security through policy enforcement while eliminating deployment time delays.
2Reliability
If manual network reconfiguration is performed during service deployment, then policy control is maintained, but operational complexity and error risk increase
Solution Approach 1:
The Map Server acts as an intermediary between border devices and services. It receives service registration information from border devices, performs automated discovery and configuration, and enforces policies centrally. This intermediary approach maintains policy control through centralized management while eliminating the need for manual reconfiguration operations at individual network devices, thereby reducing operational complexity and error risk.
Solution Approach 2:
The system implements feedback mechanisms where the Map Server continuously monitors service registrations, location changes, and policy compliance. When services are deployed or moved, they automatically register with the Map Server which then updates routing tables and policy configurations accordingly. This automated feedback loop ensures policy control is maintained dynamically without manual intervention, reducing operational complexity while preserving security and control.
3Productivity
If dynamic service deployment is enabled, then productivity and adaptability improve, but network security and policy enforcement may be compromised
Solution Approach 1:
Border devices perform preliminary actions by pre-registering their capabilities, supported services, and security policies with the Map Server before actual service deployment. The Map Server pre-configures routing tables and policy enforcement rules based on these registrations. This preliminary setup enables rapid service deployment while maintaining security, as the framework for policy enforcement is already in place and services must comply with pre-established security requirements.
Solution Approach 2:
The Map Server serves as a security intermediary that mediates between dynamically deployed services and the network infrastructure. It receives service registration requests, validates them against security policies, and only permits deployment if policies are satisfied. This intermediary role enables fast dynamic deployment while ensuring security enforcement, as the Map Server acts as a gatekeeper that automatically verifies and enforces security requirements without slowing down the deployment process.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Services with policy control may be provided. A computing device may receive registration information associated with a border device. The registration information may comprise information identifying a service provided by a server associated with the border device, information identifying the border device, and policies associated with the service. Then an address for the server may be determined. Next a request may be received comprising the information identifying the service provided by the server. In response to receiving the request comprising the information identifying the service provided by the server, the address for the server, the information identifying the border device, and the policies associated with the service may be provided.