IP Library Granted Patent US 8,966,017
Granted Patent B2
US 8,966,017 · App. 12/608,427 · Granted Feb 24, 2015

Techniques for cloud control and management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,017
App. No.
12/608,427
Granted
Feb 24, 2015
Kind
B2
Abstract

Techniques for cloud control and management are provided. The control, creation, and management of workloads in distributed infrastructures are coordinated via a master Configuration Management Database (CMDB). The master CMDB is also used to unify the multiple distributed infrastructures so that the workloads are rationalized. Moreover, data centers are coordinated with the distributed infrastructures so the configuration settings and policies included in the master CMDB are enforced and synchronized throughout the network.

Claims (28)

1. A method implemented and residing within a computer-readable storage medium that is executed by one or more processors of a network to perform the method, comprising:

configuring a master configuration management database (CMDB) with master configuration settings and master policies for construction, management, and deployment of workloads assigned to distributed computing resources of a network, the settings having attributes and relationships for each of the computing resources and between the computing resources, and at least one setting defining a communication protocol to use between two of the computing resources, and each workload defines processing loads, memory loads, storage loads, and processing capabilities for a given processing environment; and

interfacing a plurality of sub CMDB's with the master CMDB to coordinate sub configuration settings and sub policies with the master configuration settings and the master policies of the master CMDB, each sub CMDB controlling a particular set of the computing resources defining a particular distributed computing infrastructure, at least some of the master policies and the master configuration settings defined by an Infrastructure as a Service (IaaS) provider.

2. The method of claim 1 , wherein configuring further includes configuring the master CMDB to assist in enforcing identity-based security for each distributed computing infrastructure.

3. The method of claim 2 , wherein configuring further includes configuring the master CMDB to permit security specific to each distributed computing infrastructure to be maintained and enforced independent of the identity-based security within each distributed computing infrastructure.

4. The method of claim 1 , wherein configuring further includes configuring the master CMDB to permit each distributed computing infrastructure to control creation, deployment, and management of each distributed computing infrastructure's workloads as long as the sub policies and sub configuration settings are in compliance with the master policies and master configuration settings.

5. The method of claim 1 , wherein configuring further includes configuring the master CMDB to permit the distributed computing infrastructures to establish trust relationships with one another to cooperate with the workloads as long as the master policies and master configuration settings are not violated.

6. The method of claim 1 , further comprising, configuring one or more of the distributed computing infrastructures to keep the master policies and master configuration settings in synchronization with some of the sub policies and sub configuration settings of the one or more distributed computing infrastructures.

7. The method of claim 6 , wherein configuring the one or more of the distributed computing infrastructures further includes one or more of:

providing a first mapping schema to permit exchange of changes in the sub policies, the sub configuration settings, the master policies, and the master configuration settings between the one or more distributed computing infrastructures and a data center, the sub policies and the sub configuration settings in a different format from that which is associated with the master polices and the master configuration settings.

8. The method of claim 7 further comprising, keeping the master configuration settings and master policies in separate and independent synchronization with some of the sub policies and sub configuration settings of the one or more distributed computing infrastructures.

9. The method of claim 7 further comprising, ensuring that the synchronization between the one or more distributed computing infrastructures and the data center remain in compliance with the master configuration settings and the master policies of the master CMDB and separately also ensuring that any independent synchronization between the one or more distributed computing infrastructures and the master CMDB remain in compliance with the data center policies and data center configuration settings.

10. The method of claim 7 further comprising, permitting the data center to share one or more the computing resources managed within the one or more distributed computing infrastructures.

11. A method implemented and residing within a computer-readable storage medium that is executed by one or more processors of a network to perform the method, comprising:

interfacing a data center configuration management database (CMDB) for a data center with a second CMDB defined for a distributed computing environment, the data center CMDB provided by a Infrastructure as a Service (IaaS) provider and having settings for computing resources of the distributed computing environment, the settings having attributes and relationships for each of the computing resources and between the computing resources, and at least one setting defining a communication protocol to use between two of the computing resources of the distributed computing environment, and the computing resources represented as workloads, and each workload defining processing loads, memory loads, storage loads and processing capabilities for a given processing environment; and

dynamically keeping the data center CMDB in synchronization with selective portions of the second CMDB.

12. The method of claim 11 , wherein interfacing further includes using a mapping schema to translate information included in a data center schema for the data center CMDB with information included in a second schema for the second CMDB.

13. The method of claim 12 , wherein using further includes performing one or more transformations defined in the mapping schema to translate when the information in the data center schema is disparate from the information in the second schema.

14. The method of claim 11 , wherein interfacing further includes configuring the data center to share one or more computing resources controlled in the distributed computing environment.

15. The method of claim 11 , wherein interfacing further includes interfacing the second CMDB with a master CMDB, the master CMDB enforcing compliance with an Infrastructure as a Service (IaaS) provider can enforcing the compliance on the second CMDB and one or more third CMDB's.

16. The method of claim 15 , wherein interfacing the second CMDB further includes configuring the master CMDB to be notified when conflicts arise with the master CMDB in view of changes between the data center CMDB and the second CMDB, and configuring the data center CMDB to be notified when conflicts arise with the data center CMDB in view of changes between the master CMDB and the second CMDB.

17. A multiprocessor-implemented system, comprising:

one or more processors having a distributed processing environment compliance service implemented in a non-transitory computer-readable storage medium and to execute on the one or more processors of a network; and

the one or more processors also having a plurality of processing environment compliance services implemented in a non-transitory computer-readable medium and to execute on the one or more processors of the network;

the distributed processing environment compliance service configured to keep configuration settings and policies for a plurality of distributed processing environments in compliance with master configuration settings and master policies, the settings having attributes and relationships for computing resources of the distributed processing environments and the attributes and the relationships are for each of the computing resources and for between the computing resources, and at least one setting defining a communication protocol to use between two of the computing resources within a particular distributed processing environment, and the computing resources represented as workloads, and each workload defining processing loads, memory loads, storage loads and processing capabilities for a given processing environment, and each processing environment compliance service configured to manage a particular distributed processing environment and to interact with the distributed processing environment compliance service to stay in compliance and to enforce compliance on each distributed processing environment, at least some of the master configuration settings and the master policies provided by an Infrastructure as a Service (IaaS) provider.

18. The system of claim 17 , wherein the distributed processing environment compliance service and the plurality of processing environment compliance services are further configured to keep sub configuration settings and sub policies associated with each distributed processing environment in synchronization with one another.

19. The system of claim 17 , wherein the distributed processing environment compliance service is configured to audit each of the distributed processing environments for compliance.

20. The system of claim 17 , wherein distributed processing environment service and each of the processing environment compliance services are further configured to interact with an identity service to enforce identity-based security on each of the distributed processing environments.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2009
From: WIPFEL, ROBERT A.; CARTER, STEPHEN R; MCCLAIN, CAROLYN B.
To: NOVELL, INC.
Reel/Frame 023567/0918 →