Automated Virtual Machine Policy Delegation and Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional system administrator hierarchies are overwhelmed by the increased complexity and volume of virtual machines in computerized systems, struggling to manage permissions, operations, and resource allocation efficiently, especially in large-scale deployments.

Innovation Solution

Implementing automated virtual machine management systems where administrative authorities delegate policies to virtual machine managers, who in turn manage virtual machine hosts, enabling automated creation, operation, and policing of virtual machines within defined policy settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional system administrator hierarchies are used to manage virtual machines, then administrative control and security are maintained, but the administrative burden and complexity increase significantly with large numbers of virtual machines

Engineering Contradiction:
Improveadministrative controlVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated self-provisioning where virtual machine hosts automatically obtain configuration settings and credentials from policy servers without human intervention. The automated credential management system issues certificates and keys programmatically, eliminating the need for manual administrator involvement in each virtual machine deployment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical administrative processes with automated electronic systems. Policy servers automatically distribute configuration settings, and automated credential management systems issue security credentials through electronic processes rather than manual paper-based or interactive administrative procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If more system administrators are hired to manage increased virtual machine volumes, then administrative control is maintained, but operational costs increase

Engineering Contradiction:
Improveadministrative controlVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system eliminates the need for additional human administrators by implementing self-service automation where virtual machine hosts automatically provision themselves and manage their own credentials through automated interactions with policy servers, directly reducing operational costs associated with hiring and training additional administrative staff.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The automated credential management system operates continuously without interruption, automatically issuing credentials and managing security tokens as virtual machines are created and destroyed, ensuring uninterrupted administrative control while eliminating the need for additional human resources.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automated management systems are implemented, then administrative efficiency and resource utilization improve, but system complexity and policy management overhead increase

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments administrative functions into distinct modular components: policy servers that manage configuration settings, automated credential management systems that handle security credentials, and virtual machine hosts that execute workloads. This segmentation allows each component to be managed independently, reducing overall system complexity while maintaining high administrative efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policy server and automated credential management system serve multiple functions simultaneously: they distribute configuration settings to virtual machine hosts, issue security credentials, manage certificate lifecycles, and enforce security policies across diverse virtual machine workloads, reducing the need for multiple specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If manual virtual machine provisioning is used, then security and control are maintained, but the time and resources required for setup increase

Engineering Contradiction:
Improvesecurity controlVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring policy servers with security policies and credential issuance rules before virtual machine deployment. Virtual machine hosts are pre-authorized to automatically obtain credentials and configuration settings, eliminating the need for time-consuming manual security setup during provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security control procedures with automated electronic security mechanisms. The automated credential management system programmatically issues security credentials and enforces policies through electronic verification processes, maintaining security control while dramatically reducing provisioning time compared to manual administrative procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8015563B2Managing virtual machines with system-wide policies
Publication Date: 2011.09.06 SERVICENOW INC
  • US8015563B2 patent drawing
  • US8015563B2 patent drawing
  • US8015563B2 patent drawing

AI summary

An administrative authority for virtual machines can send one or more delegated policy settings to a virtual machine manager. The virtual machine manager can in turn send management instructions that include the one or more policy settings to one or more virtual machine hosts. As such, a user's request for a virtual machine at a virtual machine host can be granted or denied based on the delegated policy settings. The policy settings can be updated periodically, and can include additional information about starting, stopping, expiring, saving, or even deleting virtual machines by particular users, as well as users accessing from particular locations. In addition, an agent operating at the virtual machine host can monitor and report virtual machine activity, to ensure unauthorized virtual machines are quickly stopped and reviewed until authorized.