Remote Execution Service for Cloud Network Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in managing incidents, deploying software, and performing network buildouts due to data control policies that restrict access to certain data and the control plane, making it difficult to maintain compliance and efficiently manage restricted data.

Innovation Solution

The implementation of execution services in a remote cloud computing environment that manage workflows for monitoring, incident management, software deployment, and network buildouts, using device access services within the cloud environment to access network devices without directly interacting with restricted data, ensuring compliance with data control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If execution services are implemented in a remote cloud computing environment to manage workflows, then standardized management across different data control policies is achieved, but direct access to restricted data and network devices is prevented

Engineering Contradiction:
Improvestandardized management capabilityVSAvoiddirect access to network devices
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

A hardware proxy is introduced as an intermediary component between the execution service and network devices. The proxy resides within the cloud computing environment, has access to restricted data and network devices, and forwards requests from the execution service. This mediator enables standardized remote management while maintaining data control policy compliance by preventing direct access from outside the environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device access services are used to obtain access control data, then compliant management operations are enabled, but network latency and additional service layers are introduced

Engineering Contradiction:
Improvecompliance with data control policiesVSAvoidmanagement operation latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Access control data is cached by the hardware proxy locally within the cloud computing environment. When management operations are needed, the proxy retrieves cached credentials rather than repeatedly accessing external authentication services. This preliminary caching action reduces latency while maintaining compliance, as the proxy still operates within the environment boundaries when presenting credentials to network devices.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If the network DevOps footprint is minimized, then cloud service scalability is improved, but local operational capabilities are reduced

Engineering Contradiction:
Improvecloud service scalabilityVSAvoidlocal operational footprint
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Execution services are extracted from within the cloud computing environment and deployed in a remote location. The actual management logic and workflows are separated from the environment being managed. Only a lightweight hardware proxy remains in the cloud environment to handle local access, significantly reducing the DevOps footprint while enabling scalable remote management through the execution service.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11398953B2Standardization of network management across cloud computing environments and data control policies
Publication Date: 2022.07.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11398953B2 patent drawing
  • US11398953B2 patent drawing
  • US11398953B2 patent drawing

AI summary

Network management of cloud computing environments subject to different data control policies is standardized in a manner that ensures compliance with the data control policies. An execution service remote from a cloud computing environment being managed implements workflows to manage different aspects of the cloud computing environment, including monitoring, incident management, deployment, and/or buildout. The execution service issues requests to perform management actions for network devices in the cloud computing environment. A device access service in the cloud computing environments receives the requests, and, in response to the requests, the device access service obtains access control data to access the network devices and perform the requested management actions for the network devices.