Server Cluster Bandwidth Allocation and Security Contexts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current database management systems and data processing applications are inadequate for handling large and complex 'big data' sets, requiring thousands of hardware servers and inefficiently using network bandwidth, while traditional security models are not suitable for sensitive information in custom environments.
Innovation Solution
A computer-implemented method for managing network resources in server clusters, which determines the required bandwidth for applications, allocates network resources securely, and provisions applications across multiple switches to maximize bandwidth utilization, ensuring secure and efficient data processing and storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security models with multiple perimeters are used to protect sensitive data, then security is improved, but system complexity increases
Solution Approach 1:
The patent extracts the security function from traditional perimeter-based models and implements it at the application level through security contexts. Each application receives its own security context with embedded credentials and permissions, eliminating the need for multiple network perimeters and reducing system complexity while maintaining security.
Solution Approach 2:
The patent introduces security contexts as intermediary objects that mediate between applications and network resources. These contexts contain embedded security credentials and enforce access policies, acting as a intermediary layer that simplifies the security architecture compared to traditional multi-perimeter approaches.
2Productivity
If more network bandwidth is added to the system to handle big data processing, then data processing capacity is improved, but resource utilization efficiency deteriorates
Solution Approach 1:
The patent implements dynamic bandwidth allocation through resource allocation records that are created and destroyed based on application lifecycle. Bandwidth is allocated dynamically to applications when needed and released when not needed, allowing the system to handle big data processing efficiently without wasting bandwidth on idle resources.
Solution Approach 2:
The patent changes the bandwidth allocation parameter from static to dynamic by creating resource allocation records that specify bandwidth limits for each application. The system monitors and adjusts bandwidth usage based on application requirements and cluster capacity, improving overall resource utilization efficiency.
3Productivity
If thousands of hardware servers are deployed to process big data, then processing capability is improved, but infrastructure cost and complexity increase
Solution Approach 1:
The patent implements a universal resource allocation framework that can manage diverse computing resources (servers, storage, network) through a common interface. The cluster manager and resource allocation records provide multi-functional capability to provision and manage different types of resources uniformly, reducing infrastructure complexity while maintaining high processing capability.
Solution Approach 2:
The patent accelerates resource provisioning and management through automated cluster manager operations that rapidly allocate and configure resources. The system quickly provisions applications across the cluster with appropriate security contexts and resource allocations, enabling scalable processing capability without proportionally increasing operational complexity.
4Ease of manufacture
If network bandwidth is allocated statically to applications, then resource allocation simplicity is improved, but adaptability to varying bandwidth requirements deteriorates
Solution Approach 1:
The patent implements dynamic bandwidth allocation where resource allocation records specify bandwidth limits that can be adjusted based on application requirements. The cluster manager can modify these allocations dynamically, providing both the simplicity of structured allocation and the adaptability to varying bandwidth demands.
Solution Approach 2:
The patent performs preliminary resource allocation by creating resource allocation records before applications execute. This preliminary action establishes bandwidth limits and security contexts in advance, providing structured simplicity while allowing subsequent dynamic adjustments as application needs change.
Data Source
AI summary
In a computer-implemented method for managing network resources within a server cluster, a request for provisioning of an application to be executed by the server cluster may be received. A required amount of bandwidth for the application, and a resource allocation of network bandwidth for the application, may be determined. The application may be provisioned to a network resource within the server cluster with the resource allocation of network bandwidth. It may be determined that an additional application, which utilizes bandwidth in bursts, is to be provisioned to the server cluster. It may further be determined that the server cluster can support bandwidth requirements of the additional application, at least in part by determining that one or more applications currently provisioned to the server cluster are also utilizing bandwidth in bursts. The additional application may then be provisioned to another network resource within the server cluster.


