Multi-Tiered Server Management Architecture for Co-Location Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large numbers of servers in co-location facilities is challenging due to data security concerns, limited management functionality, and the need for efficient rights enforcement, especially with global accessibility and 24/7 operation requirements.

Innovation Solution

A multi-tiered management architecture is implemented, including an application development tier, an application operations tier, and a cluster operations tier, with local hardware management and remote software management, along with encryption to ensure data security and boundary establishment between server clusters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If servers are distributed to diverse remote locations to minimize access times, then access speed is improved, but management complexity increases

Engineering Contradiction:
Improveaccess speedVSAvoidmanagement complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The management system is segmented into multiple autonomous server nodes distributed across different locations. Each server maintains independent management capabilities while participating in a coordinated network, allowing fast local access without requiring centralized control. This segmentation enables servers to operate autonomously while still being part of a managed ecosystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical management dimension that operates alongside the geographical distribution dimension. Management functions are organized into layers (local management, regional management, central management) that coordinate across distributed locations, adding an organizational dimension to the physical distribution to manage complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If multiple servers are hosted to increase concurrent access capacity, then service availability is improved, but data security risk increases

Engineering Contradiction:
Improveservice availabilityVSAvoiddata security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The server cluster is divided into logically separated units with distinct identification and authorization. Each server or server group has unique security credentials and access controls, enabling fine-grained security management. This segmentation allows high availability through multiple servers while maintaining security through individualized protection boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces centralized authentication and authorization mechanisms that act as intermediaries between servers and data resources. This intermediary layer manages security credentials and access rights, preventing direct unauthorized access while allowing legitimate servers to operate. The intermediary coordinates security across multiple servers without requiring each server to independently manage all security aspects.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If system administrators physically travel to co-location facilities to attend to servers, then direct hardware access is improved, but time consumption increases

Engineering Contradiction:
Improvehardware accessVSAvoidtime consumption
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces the mechanical process of physical travel and manual hardware access with electronic remote management capabilities. Administrators can monitor server status, execute commands, and perform maintenance tasks through network connections, eliminating the need for physical presence at co-location facilities while maintaining full operational control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables automated monitoring and management functions that operate without human intervention. Server health is continuously monitored, and routine maintenance tasks can be executed automatically or with minimal human input, reducing the time administrators need to spend traveling to facilities for routine checks and maintenance.

Inventive Principle:
Principle #25Self-service

4Reliability

If co-location facilities provide secure areas for servers, then physical security is improved, but data isolation between companies deteriorates

Engineering Contradiction:
Improvephysical securityVSAvoiddata isolation
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The co-location facility is divided into physically separated secure areas (such as locked cages or separate rooms) for different companies. This physical segmentation maintains security while the patent adds logical segmentation through network boundaries and access controls that prevent data leakage between companies. The combination of physical and logical segmentation addresses both security and data isolation requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network boundary mechanisms and data routing controls that act as intermediaries between the physical secure areas. These intermediaries ensure that even though companies share the same physical facility, their data remains isolated through controlled network access and routing, preventing unauthorized data transfer while maintaining physical security benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7606898B1System and method for distributed management of shared computers
Publication Date: 2009.10.20 ZHIGU HLDG
  • US7606898B1 patent drawing
  • US7606898B1 patent drawing
  • US7606898B1 patent drawing

AI summary

A multi-tiered server management architecture is employed including an application development tier, an application operations tier, and a cluster operations tier. In the application development tier, applications are developed for execution on one or more server computers. In the application operations tier, execution of the applications is managed and sub-boundaries within a cluster of servers can be established. In the cluster operations tier, operation of the server computers is managed without concern for what applications are executing on the one or more server computers and boundaries between clusters of servers can be established. The multi-tiered server management architecture can also be employed in co-location facilities where clusters of servers are leased to tenants, with the tenants implementing the application operations tier and the facility owner (or operator) implementing the cluster operations tier.