Workload Domain Compliance Verification in SDDCs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for deploying workload domains in software-defined data centers (SDDCs) often result in security vulnerabilities due to compliance checks being performed after the domains are accessible, leading to potential malicious activity and the need for system reboots to implement compliance changes.

Innovation Solution

Implementing a machine-automated process that compares workload domain configurations to compliance templates before deployment, updating configurations as needed to ensure security compliance, thereby reducing vulnerabilities and eliminating the need for downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If compliance checks are performed after workload domains are deployed and accessible, then deployment speed is improved, but security reliability deteriorates due to vulnerabilities and malicious activity risks

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs compliance checks and configuration validations before deploying workload domains to production environments. The system evaluates compliance templates, checks configuration settings, and verifies security requirements in advance, ensuring that only compliant workloads are deployed. This preliminary action eliminates security vulnerabilities before they can be exploited, resolving the contradiction between fast deployment and secure reliability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If compliance changes are implemented after deployment, then deployment simplicity is improved, but system availability deteriorates due to required reboots and downtime

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent validates and enforces compliance configurations before workload deployment, ensuring that all security and operational requirements are met in advance. By performing compliance checks upfront rather than requiring post-deployment modifications, the system eliminates the need for reboots and downtime, thereby maintaining high system availability while keeping the deployment process simple.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual compliance verification is performed, then measurement precision is improved, but labor intensity increases and automation level decreases

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidautomation level
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The patent implements an automated feedback mechanism where the system continuously monitors workload configurations against compliance templates and industry standards. The compliance verification module automatically detects deviations, generates reports, and triggers corrective actions without human intervention. This automated feedback loop maintains high measurement precision while maximizing automation levels, eliminating manual verification efforts.

Inventive Principle:
Principle #23Feedback

4Reliability

If comprehensive compliance templates are enforced, then security reliability is improved, but device complexity increases due to configuration management overhead

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidconfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the system to automatically manage compliance configurations through self-service mechanisms. The compliance management module automatically applies approved templates, adjusts configurations as needed, and maintains adherence to security standards without requiring complex manual management. This self-service approach ensures high security reliability while minimizing configuration management complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11075809B2Methods and apparatus to deploy security-compliant workload domains
Publication Date: 2021.07.27 VMWARE INC
  • US11075809B2 patent drawing
  • US11075809B2 patent drawing
  • US11075809B2 patent drawing

AI summary

An example apparatus to configure a workload domain for security compliance includes a configuration normalizer to generate normalized workload domain configuration settings by normalizing workload domain configuration settings of a deployed workload domain based on a format of compliance configuration settings; a drift comparator to compare the normalized workload domain configuration settings with the compliance configuration settings before deploying an application in the workload domain; a post start-up controller to generate updated workload domain configuration settings by modifying ones of the workload domain configuration settings, the modifying of the ones of the workload domain configuration settings being based on the comparison of the normalized workload domain configuration settings with the compliance configuration settings; and a compliance verifier to determine whether the updated workload domain configuration settings satisfy the compliance configuration settings.