Virtual Instance Provisioning for Secure Cloud Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high initial costs and complexity of deploying enterprise application software using traditional three-tiered architecture make it inaccessible to small and medium businesses, while existing cloud computing solutions lack secure and reliable integration with private data centers.

Innovation Solution

A system and method for provisioning and managing computing applications on virtual instances within a public virtualization space, utilizing a hosted service system that provides automated administration, encrypted networking, and secure integration between private and public environments, hiding the underlying virtualization service and network insecurity, and offering secure, reliable, and performant instances comparable to local deployments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional three-tiered architecture is used for enterprise application deployment, then application functionality and reliability are ensured, but initial deployment cost and complexity increase substantially

Engineering Contradiction:
Improveapplication functionalityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the traditional three-tiered architecture by deploying it as a virtual instance in the cloud. The virtual instance replicates the entire application stack (user interface tier, server tier, database tier) without requiring physical hardware deployment, thereby maintaining application functionality while dramatically reducing deployment complexity and initial costs

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the physical cloud infrastructure and the traditional three-tiered architecture. This virtualization layer abstracts the complexity of cloud resource management and presents a familiar on-premises-like interface, allowing enterprises to migrate applications without redesigning their architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional three-tiered architecture is deployed locally, then application security and control are maintained, but hardware and infrastructure costs increase

Engineering Contradiction:
Improveapplication securityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates a virtual copy of the traditional three-tiered architecture by deploying it as a virtual instance in the cloud. The virtual instance replicates the entire application stack (user interface tier, server tier, database tier) without requiring physical hardware deployment, thereby maintaining application functionality while dramatically reducing deployment complexity and initial costs

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements a universal virtualization platform that can host multiple different three-tiered applications on shared physical hardware. The same physical servers, storage, and networking infrastructure can support various enterprise applications simultaneously through virtualization, eliminating the need for dedicated hardware for each application

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If cloud computing is used to host applications, then shared resources and cost structure are improved, but security and reliability concerns arise

Engineering Contradiction:
Improvecost structureVSAvoidintegration security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary between the physical cloud infrastructure and the traditional three-tiered architecture. This virtualization layer abstracts the complexity of cloud resource management and presents a familiar on-premises-like interface, allowing enterprises to migrate applications without redesigning their architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical components (database tier, server tier) from the public cloud environment and places them in a private virtual network isolated from public-facing services. This extraction maintains the cost benefits of cloud computing while addressing security concerns by separating sensitive data and processing from the shared public infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If virtual instances are deployed in public virtualization space, then scalability and resource sharing are improved, but network security and integration complexity increase

Engineering Contradiction:
ImprovescalabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network into isolated virtual subnets that mirror traditional on-premises network topology. Each tier of the three-tiered architecture is placed in its own virtual subnet with controlled access points, allowing scalable cloud deployment while maintaining familiar network security boundaries and reducing integration complexity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9569240B2Method and system to provision and manage a computing application hosted by a virtual instance of a machine
Publication Date: 2017.02.14 ADOBE INC
  • US9569240B2 patent drawing
  • US9569240B2 patent drawing
  • US9569240B2 patent drawing

AI summary

A system and method are described for provisioning and managing virtual instances of a computing application running within a public virtualization space (referred to as a hosted service system). A hosted service system may be configured to provide automated administration of the computing application, replacing the administration tasks that would otherwise be performed by the customer when running in an on-premise production deployment and to provide encrypted networking and other services that are specific to the public virtualization environment and are designed to provide a secure integration fabric between a customer's own private data center and virtual instances of the computing application running within an insecure public virtualization service.