Virtual Private Cloud Resource Activity Management via Distributed Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing in-virtual network activities within cloud environments is challenging due to difficulties in scaling, security vulnerabilities, and manual configuration errors associated with existing methods such as making VPCs public, VPC peering, and private link services.

Innovation Solution

Deploying lightweight sensors within each virtual network as executable packages, managed independently, to monitor and manage activities without a public interface, using orchestration engines and serverless functions for task execution and lifecycle management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPCs are made public to enable activity management, then ease of operation is improved, but security vulnerabilities worsen

Engineering Contradiction:
Improveactivity management capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces sensors as intermediary components deployed within each VPC to enable activity management without exposing the VPC to the public. These sensors act as mediators between the management system and the VPC resources, allowing controlled monitoring and management while maintaining security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the management function by deploying independent sensors in each VPC rather than making the entire VPC accessible. Each sensor operates independently within its respective VPC, enabling distributed management capability while maintaining security boundaries between different VPCs.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If VPC peering is used to connect virtual networks, then adaptability is improved, but device complexity worsens

Engineering Contradiction:
Improvenetwork connectivity flexibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of establishing complex peering connections between VPCs, the patent deploys copies of the same sensor type in each VPC. These sensors replicate the necessary management functionality locally, eliminating the need for complex inter-VPC connectivity configurations while maintaining adaptability through the distributed sensor network.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If private link services are implemented, then security is improved, but ease of operation worsens

Engineering Contradiction:
Improvesecurity protectionVSAvoidactivity management accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The sensors deployed within each VPC perform self-service by autonomously executing management tasks and monitoring activities locally. This eliminates the need for complex private link configurations while maintaining security, as the sensors operate independently within their respective VPCs without requiring external connectivity.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If sensors are deployed in each virtual network independently, then scalability is improved, but device complexity worsens

Engineering Contradiction:
Improvescaling capabilityVSAvoidsensor deployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs universal sensor packages that can be deployed across different VPCs using the same executable format. These multi-functional sensors handle various management tasks within each VPC, enabling scalable deployment without increasing operational complexity, as the same sensor type can be instantiated in any number of VPCs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12086043B1Virtual private cloud resource activity management
Publication Date: 2024.09.10 PROOFPOINT INC
  • US12086043B1 patent drawing
  • US12086043B1 patent drawing
  • US12086043B1 patent drawing

AI summary

The technology disclosed relates to resource activity management in a cloud environment. A computer-implemented method includes detecting a plurality of virtual networks in the cloud environment and deploying a plurality of sensors in the plurality of virtual networks using an orchestration engine of the cloud environment. Each sensor, of the plurality of sensors, includes an executable package configured to execute in a respective virtual network, of the plurality of virtual networks, independent of other sensors, of the plurality of sensors, to manage activities in the respective virtual network. The method includes identifying an activity management task to be performed in a particular virtual network of the plurality of virtual networks, sending a task command representing the activity management task to the sensor deployed in the particular virtual network, and receiving an execution result representing execution of the activity management task by the sensor deployed in the particular virtual network.