Traffic Management System Authorization for Secure Workload Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized environments, managing and redirecting data traffic across subnets and servers is challenging due to the lack of automatic traffic forwarding and inadequate authorization controls, leading to potential misdirection of workloads and security concerns.
Innovation Solution
A data traffic management system that includes a management tool and network device configured to authorize and redirect traffic based on predefined authorization rules, ensuring that only authorized administrators can reconfigure policy routing and migrate traffic streams securely across subnets, using a dynamic switch configuration and authentication features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If administrators manually redirect traffic using Policy Based Routing or Policy Based Forwarding, then traffic can be redirected to specific servers, but the system becomes susceptible to misdirection of workloads and lacks automatic authorization controls
Solution Approach 1:
The patent introduces an intermediary authorization system that mediates between administrators and traffic redirection operations. This intermediary layer validates administrator credentials and authorization rules before allowing traffic redirection, preventing misdirection while maintaining operational capability. The system acts as a trusted third party that verifies both the administrator's identity and the legitimacy of the redirection request.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors traffic redirection operations and compares them against stored authorization rules. When a redirection attempt occurs, the system provides immediate feedback by validating the administrator's credentials and the requested action against predefined policies, allowing only authorized redirections to proceed while blocking unauthorized ones.
2Adaptability or versatility
If workload is moved from one subnet, server, or application to another, then resource utilization improves, but saved parameters become inapplicable and traffic management becomes difficult
Solution Approach 1:
The patent applies preliminary action by pre-configuring authorization rules and credentials in the system before workload movements occur. These predefined policies establish the framework for future traffic redirection operations, allowing the system to automatically handle workload mobility without requiring complex real-time management decisions. The preliminary setup includes defining which administrators can redirect traffic and under what conditions.
Solution Approach 2:
The patent creates a universal authorization system that handles multiple types of workload movements across different subnets, servers, and applications through a single unified mechanism. This multi-functional approach allows the same authorization framework to manage diverse traffic redirection scenarios, reducing the need for separate management systems for each type of workload movement.
3Ease of operation
If administrators are given reconfiguration rights for policy routing, then traffic redirection is enabled, but security concerns arise from potential unauthorized data movement
Solution Approach 1:
The patent implements preliminary anti-action by pre-establishing authorization rules that prevent unauthorized traffic redirection before it can occur. The system proactively blocks potential harmful actions by validating administrator credentials and requested operations against predefined policies before allowing any traffic redirection to take place, thus preventing security violations rather than merely detecting them afterward.
Data Source
AI summary
Systems, devices, and methods for traffic management are provided. An example of a method for traffic management includes receiving a number of policies for data traffic redirection 230 in a data network 100 and authorizing a subset of the number of policies based upon matching a plurality of authorization rules 350 saved in the data network 100, for example, in a management tool 120 and/or a network device 123.


