Virtual Remote Support Client for Secure Software-Defined System Debugging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined computing systems face challenges in remotely identifying and correcting performance bottlenecks due to complex network communications and security constraints, making traditional remote debugging methods cumbersome and insecure.

Innovation Solution

A method is introduced where a hypervisor initializes two virtual machines, with one executing a service application and the other deploying a lightweight virtual remote support connectivity client to enable remote monitoring through logical data connections, using the first virtual machine as a proxy to access the software-defined computing system, even during network errors, and allowing debugging and maintenance via secure channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional screen-sharing solutions are used for remote debugging, then remote monitoring capability is provided, but security constraints and network complexity increase

Engineering Contradiction:
Improveremote monitoring capabilityVSAvoidsecurity constraints and network complexity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a remote support connectivity client as an intermediary component that runs within the virtualized environment. This client acts as a secure mediator between the remote support provider and the software-defined computing system, enabling remote monitoring while maintaining security boundaries. The intermediary approach allows debugging operations without requiring direct access to the host system, thus resolving the contradiction between ease of remote operation and security constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct remote access to the host system is implemented, then debugging efficiency is improved, but system security and stability are compromised

Engineering Contradiction:
Improvedebugging efficiencyVSAvoidsystem security and stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the remote support functionality into a separate virtual machine instance. By creating a dedicated virtual machine for remote support operations, the system allows efficient debugging while isolating the host environment. This segmentation ensures that remote access operations are contained within a controlled virtual boundary, preventing potential security risks from affecting the main system while maintaining full debugging capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If virtual machines are used for remote support, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity enhancementVSAvoidvirtualization infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing hypervisor infrastructure to provide remote support functionality. The virtual machine used for remote support serves multiple purposes: it acts as a secure containment environment, provides the remote support connectivity client runtime, and can be integrated with the existing virtualized storage and computing resources. This multi-functionality approach enhances security while minimizing the addition of complex new infrastructure components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10353732B2Software-defined computing system remote support
Publication Date: 2019.07.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10353732B2 patent drawing
  • US10353732B2 patent drawing
  • US10353732B2 patent drawing

AI summary

Methods, computing systems and computer program products implement embodiments of the present invention that include initializing, by a hypervisor executing on a processor, first and second virtual machines. A first software application configured to provide a service is executed on the first virtual machine, and a logical data connection is established between the first and the second virtual machines. Examples of the logical connection include physical and virtual serial connections, and physical and virtual data networking connections. A second software application configured to enable remote monitoring of the first software application via the logical data connection is executed on the second virtual machine. In some embodiments, the second software application can remotely monitor the first software application via an interface such as a command line interface, a graphical user interface and an application programming interface.