Verified Add-on Resource API for Cloud Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud software platforms face challenges in managing and securing add-ons across independently operating software platforms, making it difficult for administrators to address vulnerabilities and maintain security without manual labor and cooperation from multiple platform administrators.

Innovation Solution

Implementing a verified add-on resource API that allows platform orchestrators to centrally manage and modify add-ons installed on software platforms, enabling automatic upgrading or disabling of problematic add-ons and rapid assessment of security impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If platform orchestrators allow independently operating software platforms to be launched by development teams, then self-service capability is improved, but security management and vulnerability response become difficult and require significant manual labor

Engineering Contradiction:
Improveself-service capabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments security management by introducing a dedicated security component that operates independently within each software platform. This security component can be individually managed and updated without affecting other platforms, allowing centralized security policies to be enforced while maintaining platform independence. The segmentation enables granular control over security operations across multiple platforms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized security management intermediary is introduced that acts as a mediator between development teams and security administrators. This intermediary component enables security administrators to push security updates and patches to add-ons across independently operating platforms without requiring direct intervention from platform administrators, thus maintaining self-service while simplifying security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple independently operating software platforms are deployed, then developer autonomy is improved, but coordinated security updates and vulnerability patching require participation from many platform administrators

Engineering Contradiction:
Improvedeveloper autonomyVSAvoidsecurity update efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements preliminary action by pre-configuring security update mechanisms and authorization frameworks during platform deployment. Security update policies, digital signatures, and distribution channels are established in advance, enabling automatic security patching without requiring real-time coordination among multiple administrators when vulnerabilities are discovered.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each software platform is equipped with self-service security update capabilities that automatically receive, verify, and install security patches from the centralized security component. The platforms can autonomously manage their own security updates through predefined policies, eliminating the need for manual coordination among multiple platform administrators while maintaining developer autonomy.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual coordination among platform administrators is required for security updates, then platform independence is maintained, but response time to address vulnerabilities increases

Engineering Contradiction:
Improveplatform independenceVSAvoidvulnerability response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements continuous feedback mechanisms where security components across independently operating platforms report their status, vulnerability information, and update readiness to a centralized security management system. This feedback loop enables real-time monitoring and coordinated response to vulnerabilities while preserving platform independence, as each platform receives and processes security updates based on its own operational state and feedback from the centralized system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12079640B1Platform verified add-on resources
Publication Date: 2024.09.03 PIVOTAL SOFTWARE INC
  • US12079640B1 patent drawing
  • US12079640B1 patent drawing
  • US12079640B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media for a platform orchestrator to use verified add-on resources. One of the methods includes receiving, by a platform orchestrator, an add-on resource API command that references an add-on resource installed on one or more software platforms launched by the platform orchestrator. A request to execute the add-on resource API command is provided to a platform controller of a software platform of the one or more software platforms launched by the platform orchestrator. The add-on resource API command is executed including identifying one or more instances of the add-on resource referenced by the add-on resource API command that are executed as workloads on the software platform launched by the platform orchestrator.