Trust Index Workload Placement in Converged Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed infrastructure systems face challenges in ensuring proper deployment, operation, and performance, particularly in ensuring trust and security capabilities across information handling resources, leading to inefficiencies and increased costs.

Innovation Solution

A method and system that calculates a trust index for each information handling system based on discovered trust and security information, using a trust and security algorithm, to influence the placement of virtual machines and application services, employing discovery adapters across various architectural layers and exposing trust and security awareness to infrastructure services managers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional horizontal data center architecture is used to reduce costs and improve utilization, then resource consolidation is improved, but security and trust management becomes fragmented and difficult to ensure across distributed resources

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary layer (security domain model and trust index calculation mechanism) between the fragmented physical resources and the workload placement decisions. This intermediary aggregates security information from distributed resources into unified security domains, enabling centralized security management while maintaining the benefits of horizontal architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the infrastructure into distinct security domains based on trust characteristics, allowing workloads to be placed in appropriate domains. This segmentation enables fine-grained security management where each domain can have its own security policies and trust levels, resolving the fragmentation issue while maintaining resource consolidation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security checks and trust verification are performed thoroughly for each workload placement, then security assurance is improved, but deployment time and operational complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary security domain discovery and trust index calculation before workload placement. By pre-characterizing infrastructure resources with security domains and trust indices, the system avoids time-consuming security checks during actual deployment, as placement decisions can rely on pre-computed trust metrics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms complex security verification into a simplified parameter comparison by using trust indices. Instead of performing thorough security checks for each workload, the system compares trust index values and security domain attributes, significantly reducing deployment time while maintaining security compliance.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security domains and trust indices are calculated and enforced for all workloads, then security awareness is improved, but system complexity and management overhead increases

Engineering Contradiction:
Improvetrust and security capabilityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security domain model that can be applied across different workload types, infrastructure platforms, and security requirements. This single framework handles diverse security needs through standardized trust indices and domain definitions, reducing management complexity despite enhanced security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10417431B2Security domains for aware placement of workloads within converged infrastructure information handling systems
Publication Date: 2019.09.17 DELL PROD LP
  • US10417431B2 patent drawing
  • US10417431B2 patent drawing
  • US10417431B2 patent drawing

AI summary

Disclosed methods and systems discover trust and security information indicative of trust and security capabilities of information handling resources. Based on the trust and security information and a corresponding algorithm, a trust index may be calculated for a particular system. Trust index values may be used to influence subsequent placements of virtual machines, application services, or other objects. Discovery may include invoking resource-specific trust and security discovery adapters to access a resource manifest indicating an interface and trust and discovery artifacts associated with the resource of interest and determine which, if any, of the applicable trust and discovery artifacts are implemented in the applicable system. The trust index may be calculated by determining which trust and security artifacts a particular system includes and, for each such artifact, multiplying a trust assessment assigned to the artifact by a user configurable weighting and summing the resulting products for each artifact.