IP Library Granted Patent US 8,745,205
Granted Patent B2
US 8,745,205 · App. 12/725,241 · Granted Jun 3, 2014

System and method for intelligent workload management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,745,205
App. No.
12/725,241
Granted
Jun 3, 2014
Kind
B2
Abstract

The system and method for intelligent workload management described herein may include a computing environment having a model-driven, service-oriented architecture for creating collaborative threads to manage workloads, wherein the management threads may converge information for managing identities and access credentials, enforcing policies, providing compliance assurances, managing provisioned and requested services, and managing physical and virtual infrastructure resources. In one implementation, an authentication server may generate authentication tokens defining access credentials for managed entities across a plurality of authentication domains, wherein the authentication tokens may control access to resources in an information technology infrastructure. For example, a management infrastructure may create service distributions for the managed entities, which may include virtual machine images hosted on physical resources. Further, the authentication tokens may be embedded in the service distributions, whereby the embedded authentication tokens may control access to the resources in the information technology infrastructure.

Claims (56)

1. A system for intelligent workload management, comprising:

an identity vault that stores federated information defining a unique identity for at least one managed entity across a plurality of authentication domains, the unique identity in the identity vault including abstractions that provide access to authoritative attributes, active roles, and valid policies for the at least one managed entity, and wherein the at least one managed entity includes other unique identities in the identity vault, the unique identity and each of the other unique identities include different roles from one another and at least one identity and at least one identity providing complete anonymity for the at least one managed entity;

an authentication server that generates an authentication token defining authorizations or permissions assigned to the unique identity across the plurality of authentication domains, wherein the authentication server generates the authentication token for the at least managed entity associated with the unique identity from the federated information stored in the identity vault;

an information technology infrastructure that includes a network having a plurality of physical resources and one or more storage systems; and

a management infrastructure that manages one or more services for the at least one managed entity, wherein the management infrastructure is configured to:

create a service distribution for the at least one managed entity, wherein the service distribution includes one or more virtual machine images hosted on one or more of the plurality of physical resources, and wherein the service distribution created for the at least one managed entity partitions the one or more hosted virtual machine images into a physical distribution layer and a virtual distribution layer;

embed the authentication token that defines the authorizations or permissions assigned to the unique identity in the service distribution, wherein the embedded authentication token controls access to the information technology infrastructure;

insert a management agent within the service distribution at an injection point in the physical distribution layer, wherein the management agent monitors one or more events associated with the service distribution; and

remove the management agent from the service distribution in response to determining that the management agents have completed the tasks to manage the service distribution

audit a lifecycle for the service distribution, wherein auditing the lifecycle for the service distribution includes analyzing the monitored events for compliance with one or more policies or compliance with a workload profile defined for the service distribution

wherein the virtual distribution layer includes a storage pointer that identifies a storage location allocated to the service distribution in the one or more storage systems, an operating system that runs one or more applications, and a workload profile that defines configurations for one or more of the storage pointer, the operating system, or the one or more applications; and

wherein the physical distribution layer includes a functional kernel, one or more hardware drivers, a hypervisor, and one or more software packages that collectively provide an interface from the virtual distribution layer to the one or more physical resources in the network that host the virtual machine images in the service distribution.

2. The system of claim 1 , wherein auditing the lifecycle for the service distribution further includes:

tracking an evolution of the lifecycle for the service distribution, wherein the evolution of the lifecycle for the service distribution includes one or more changes applied to the service distribution across a plurality of lifecycle modes associated with the service distribution;

retiring the service distribution, wherein retiring the service distribution includes de-provisioning any existing versions of the service distribution, including the service distribution created for the managed entity; and

re-releasing a modified version of the service distribution to an image repository, wherein the modified version of the service distribution re-released to the image repository includes at least one of the changes applied to the service distribution during the lifecycle evolution for the service distribution.

3. A system for intelligent workload management, comprising:

an identity vault that stores federated information defining a unique identity for at least one managed entity across a plurality of authentication domains, the unique identity in the identity vault including abstractions that can provide access to authoritative attributes, active roles, and valid policies for the at least one managed entity, and wherein the at least one managed entity includes other unique identities in the identity vault, the unique identity and each of the other unique identities include different roles from one another and at least one identity providing complete anonymity for the at least one managed entity;

an authentication server that generates an authentication token defining authorizations or permissions assigned to the unique identity across the plurality of authentication domains, wherein the authentication server generates the authentication token for the at least one managed entity associated with the unique identity from the federated information stored in the identity vault;

an information technology infrastructure that includes a network having a plurality of physical resources and one or more storage systems; and

a management infrastructure that manages one or more services for the at least one managed entity, wherein the management infrastructure is configured to:

create a service distribution for the at least one managed entity, wherein the service distribution includes one or more virtual machine images hosted on one or more of the plurality of physical resources in the network;

embed an authentication token that defines the authorizations or permissions assigned to the unique identity in the service distribution, wherein the embedded authentication token controls access to the information technology infrastructure;

wherein the service distribution created for the at least one managed entity partitions the one or more hosted virtual machine images into a physical distribution layer and a virtual distribution layer;

wherein the virtual distribution layer includes a storage pointer that identifies a storage location allocated to the service distribution in the one or more storage systems, an operating system that runs one or more applications, and a workload profile that defines configurations for one or more of the storage pointer, the operating system, or the one or more applications;

wherein the physical distribution layer includes a functional kernel, one or more hardware drivers, a hypervisor, and one or more software packages that collectively provide an interface from the virtual distribution layer to the one or more physical resources in the network that host the virtual machine images in the service distribution; and

wherein the physical distribution layer further includes a management agent injection point, and wherein the management infrastructure is further configured to:

insert one or more management agents within the service distribution at the injection point, wherein the inserted management agents are configured to execute one or more tasks to manage the service distribution; and

remove the one or more management agents from the service distribution in response to determining that the management agents have completed the tasks to manage the service distribution.

4. The system of claim 3 , wherein the management infrastructure is further configured to restore a state of the service distribution in response to removing the one or more management agents from the service distribution.

5. The system of claim 4 , wherein the management infrastructure removes a runtime state for the management agents from the service distribution and rolls back one or more changes that the management agents applied to the service distribution in order to execute the one or more tasks to restore the state of the service distribution.

6. The system of claim 3 , wherein the management infrastructure is further configured to:

identify a current lifecycle mode associated with the service distribution, wherein the inserted management agents are associated with the identified mode; and

determine that the management agents have completed the tasks to manage the service distribution in response to one or more policies permitting a change from the current lifecycle mode to another lifecycle mode.

7. The system of claim 6 , wherein the current lifecycle mode associated with the service distribution includes one or more of a creation mode, a release mode, a production mode, a maintenance mode, a re-release mode, or a retirement mode.

8. The system of claim 3 wherein the physical distribution layer, further includes a management agent injection point, and wherein the management infrastructure is further configured to:

insert one or more management agents within the service distribution at the injection point, wherein the inserted management agents are configured to execute one or more tasks to manage the service distribution; and

remove the one or more management agents from the service distribution in response to determining that the management agents have completed the tasks to manage the service distribution.

9. A method for intelligent workload management, comprising:

storing, in an identity vault, federated information defining a unique identity for at least one managed entity across a plurality of authentication domains, the unique identity in the identity vault including abstractions that can provide access to authoritative attributes, active roles, and valid policies for the at least one managed entity, and wherein the at least one managed entity includes other unique identities in the identity vault, the unique identity and each of the other unique identities include different roles from one another and at least one identity providing complete anonymity for the at least one managed entity;

generating, at an authentication server, an authentication token defining authorizations or permissions assigned to the unique identity across the plurality of authentication domains, wherein the authentication server generates the authentication token for the at least one managed entity associated with the unique identity from the federated information stored in the identity vault;

creating, at a management infrastructure, a service distribution for the at least one managed entity, wherein the service distribution includes one or more virtual machine images hosted on one or more of a plurality of physical resources in an information technology infrastructure that includes a network having the plurality of physical resources and one or more storage systems; and

embedding the authentication token that defines the authorizations or permissions assigned to the unique identity in the service distribution created for the at least one managed entity, wherein the embedded authentication token controls access to the information technology infrastructure;

wherein the service distribution created for the at least one managed entity partitions the one or more hosted virtual machine images into a physical distribution layer and a virtual distribution layer,

wherein the virtual distribution layer includes a storage pointer that identifies a storage location allocated to the service distribution in the one or more storage systems, an operating system that runs one or more applications, and a workload profile that defines configurations for one or more of the storage pointer, the operating system, or the one or more applications, and

the physical distribution layer includes a functional kernel, one or more hardware drivers, a hypervisor, and one or more software packages that collectively provide an interface from the virtual distribution layer to the one or more physical resources in the network that host the virtual machine images in the service distribution,

wherein the physical distribution layer further includes a management agent injection point, and wherein the method further comprises:

inserting one or more management agents within the service distribution at the injection point, wherein the inserted management agents are configured to execute one or more tasks to manage the service distribution; and

removing the one or more management agents from the service distribution in response to determining that the management agents have completed the tasks to manage the service distribution.

10. The method of claim 9 , further comprising restoring a state of the service distribution in response to removing the one or more management agents from the service distribution, wherein restoring the state of the service distribution includes:

removing a runtime state for the management agents from the service distribution; and

rolling back one or more changes that the management agents applied to the service distribution in order to execute the one or more tasks.

11. The method of claim 9 , further comprising:

identifying a current lifecycle mode associated with the service distribution, wherein the inserted management agents are associated with the identified lifecycle mode; and

determining that the management agents have completed the tasks to manage the service distribution in response to one or more policies permitting a change from the current lifecycle mode to another lifecycle mode.

12. The method of claim 11 , wherein the current lifecycle mode associated with the service distribution includes one or more of a creation mode, a release mode, a production mode, a maintenance mode, a re-release mode, or a retirement mode.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2010
From: ANDERSON, ERIC W. B.; WIPFEL, ROBERT; KOHARI, MOIZ
To: NOVELL, INC.
Reel/Frame 024089/0103 →