Service Mesh Proxy for Secure Data Center Workload Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based data center management systems face challenges with one-way communication channels that are hindered by firewalls, proxies, and complex network setups, making real-time, secure management of data center assets on customer premises difficult.

Innovation Solution

A method and system for performing connectivity management operations using a data center asset client module and a host operating system agent, establishing a secure communication channel with a connectivity management system featuring a service mesh proxy, enabling bidirectional communication and remote workload orchestration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-way communication channel is used through firewalls and proxies, then network security is maintained, but real-time bidirectional management of data center assets becomes difficult

Engineering Contradiction:
Improvenetwork securityVSAvoidreal-time management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a service mesh proxy as an intermediary component that establishes a secure tunnel between the data center asset and the cloud-based management system. This proxy acts as a local gateway that enables bidirectional communication while maintaining security boundaries, allowing real-time workload orchestration and asset management without requiring direct access to the customer's network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a secure tunnel is established for bidirectional communication, then real-time management capability is improved, but system complexity increases

Engineering Contradiction:
Improvereal-time management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional components: a service mesh proxy deployed on the customer's data center asset, a connectivity management system in the cloud, and integrated agents within the host operating system. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while enabling sophisticated real-time management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service mesh proxy is designed to self-configure and establish secure connections automatically without requiring manual network configuration. The integrated agents within the host operating system autonomously manage workload orchestration and asset management tasks, reducing the operational burden and complexity for system administrators.

Inventive Principle:
Principle #25Self-service

3Productivity

If cloud-based management is implemented, then management efficiency is improved, but communication barriers from firewalls and proxies increase

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidcommunication barriers
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The service mesh proxy is pre-deployed on the data center asset before cloud-based management is initiated. This preliminary action establishes the communication pathway in advance, allowing the cloud management system to connect and orchestrate workloads without encountering firewall or proxy barriers during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11943124B2Data center asset remote workload execution via a connectivity management workload orchestration operation
Publication Date: 2024.03.26 DELL PROD LP
  • US11943124B2 patent drawing
  • US11943124B2 patent drawing
  • US11943124B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a data center connectivity management operation. The connectivity management operation includes: providing a data center asset with a data center asset client module and a host operating system agent; establishing a secure communication channel between the data center asset client module and a connectivity management system, the connectivity management system comprising a service mesh proxy; exchanging information between the data center asset and the connectivity management system via the secure communication channel between the data center asset and the connectivity management system; and, remotely executing a workload on the data center asset via a workload orchestration operation, the service mesh proxy communicating with the host operating system agent when performing the workload orchestration operation.