Policy Unification Framework for Software-Defined Datacenter Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined datacenters, diverse policy sources and implementations across different platforms lead to confusion and complexity for datacenter managers, making it difficult to coordinate higher-level business requirements and manage resources efficiently.

Innovation Solution

A policy unification framework that imports and normalizes policies from various sources, binds them to resources based on categorization, and provides policy bindings to policy engines, allowing for the creation of composite policies and handling exceptions, thereby simplifying policy management across heterogeneous environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple policy sources and implementations are used across different platforms, then diverse policy options and specialized management capabilities are available, but confusion and complexity increase for datacenter managers

Engineering Contradiction:
Improvepolicy optionsVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple policy sources and implementations into a unified policy framework. The system integrates policies from different platforms (virtual machine placement, networking configurations, storage management, etc.) into a single coherent structure that can be centrally managed, thereby maintaining diverse policy options while reducing management complexity through unification

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified policy framework serves multiple functions simultaneously: it manages diverse policy types from different platforms, provides centralized coordination, enables consistent policy enforcement across heterogeneous environments, and offers a common interface for policy administration. This multi-functional approach allows a single system to handle various policy management tasks that previously required separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple configurations across multiple components are coordinated to implement higher-level business requirements, then comprehensive policy enforcement is achieved, but coordination difficulty and complexity increase

Engineering Contradiction:
Improvepolicy enforcement consistencyVSAvoidcoordination ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The unified policy framework acts as an intermediary layer between higher-level business requirements and multiple underlying configurations across different components. It receives policy inputs, processes them through a standardized framework, and distributes appropriate configurations to various components (virtual machine placement systems, networking configurations, storage managers, etc.), thereby ensuring consistent enforcement while simplifying the coordination burden

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the complex coordination task into manageable parts by maintaining separate policy definitions for different components while providing a unified mechanism for their integration. Each component's configuration can be independently defined and managed, yet the unified framework coordinates them together to achieve comprehensive policy enforcement, making the overall system more operable

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10263847B2Policy validation
Publication Date: 2019.04.16 VMWARE INC
  • US10263847B2 patent drawing
  • US10263847B2 patent drawing
  • US10263847B2 patent drawing

AI summary

Some embodiments provide method for managing a set of computing resources. The method receives information for a set of resources. The information for each resource indicates a set of policies bound to the resource. The policies as bound to the resources are for application by several policy engines. For each of several of the resources, the method determines whether the policies bound to the resource violate a set of policy validation rules. For a subset of the resources for which a violation exists, the method disables at least one of the policies from being applied to the resource by the several policy engines.