Overlay Network Message Bus for Hybrid Cloud Container Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In hybrid cloud architectures, correlating vulnerabilities and managing ephemeral resources across different cloud networks is challenging, especially when migrating workloads from legacy systems to public clouds, due to the short-lived nature of resources and the complexity of breaking legacy inventory models.
Innovation Solution
An overlay network with a message bus is instantiated between cloud networks, enabling communication and resource sharing, such as container images, across private and public cloud networks, using software-defined network (SDN) elements and dedicated interfaces to facilitate container creation, updates, and resource management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If resources are migrated to vendor-hosted cloud, then scalability and dynamic resource availability are improved, but resource lifespan becomes extremely short (ephemeral) making vulnerability correlation difficult
Solution Approach 1:
The patent introduces an intermediary system that correlates cloud resources with legacy inventory through shared identifiers. This mediator enables vulnerability tracking across the ephemeral nature of cloud resources while maintaining connection to persistent legacy systems, resolving the contradiction between short resource lifespan and the need for ongoing vulnerability correlation.
Solution Approach 2:
The patent creates a copy of inventory data and vulnerability information between cloud and legacy environments using shared identifiers. This copying mechanism allows vulnerability correlation to persist even when original cloud resources are ephemeral, as the correlated data is replicated and maintained across both environments.
2Adaptability or versatility
If legacy inventory models are broken during cloud migration, then cloud-native resource management is improved, but correlation between cloud resources and legacy business units is lost
Solution Approach 1:
The patent implements copying of inventory and vulnerability data between legacy and cloud environments using shared identifiers. This ensures that when legacy inventory models are broken or abandoned in favor of cloud-native approaches, the vulnerability correlation information is replicated and preserved, preventing information loss.
Solution Approach 2:
The shared identifier system serves multiple functions: it identifies cloud resources, links them to legacy inventory, and maintains vulnerability correlation across both environments. This universal identifier mechanism allows the system to maintain correlation without being constrained by traditional legacy inventory models.
3Productivity
If container images are shared across private and public cloud networks, then resource utilization and container creation speed are improved, but network complexity and security management increase
Solution Approach 1:
The overlay network acts as an intermediary layer between private and public cloud networks, enabling container image sharing while abstracting away the underlying network complexity. This mediator allows fast container creation through efficient image distribution while managing security and network management concerns at the overlay layer.
Solution Approach 2:
The patent introduces an overlay network dimension that operates above the physical network infrastructure. This additional dimensional layer enables container image sharing across hybrid cloud environments without directly increasing physical network complexity, as the overlay operates in a virtualized network space.
Data Source
AI summary
Concepts and technologies disclosed herein are directed to service correlation across hybrid cloud architecture to support container hybridization. According to one aspect of the concepts and technologies disclosed herein, an overlay network can instantiate a message bus between a first cloud network and a second cloud network. The overlay network can receive, via the message bus, a request from the second cloud network for a container image stored in a containerized application asset repository of the first cloud network. The overlay network can retrieve, via the message bus, the container image from the containerized application asset repository. The overlay network can provide, via the message bus, the container image to the second cloud network for creating a container based upon the container image.


