IP Library Granted Patent US 8,695,075
Granted Patent B2
US 8,695,075 · App. 12/762,015 · Granted Apr 8, 2014

System and method for discovery enrichment in an intelligent workload management system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,695,075
App. No.
12/762,015
Granted
Apr 8, 2014
Kind
B2
Abstract

The system and method described herein for discovery enrichment in an intelligent workload management system may include a computing environment having a model-driven, service-oriented architecture for creating collaborative threads to manage workloads. In particular, the management threads may converge information for managing identities and access credentials, which may provide information that can enrich discovery of physical and virtual infrastructure resources. For example, a discovery engine may reference federated identity information stored in an identity vault and enrich a discovered infrastructure model with the federated identity information. Thus, the model may generally include information describing physical and virtualized resources in the infrastructure, applications and services running in the infrastructure, and information derived from the federated identity information that describes dependencies between the physical resources, the virtualized resources, the applications, and the services.

Claims (44)

1. A system for discovery enrichment in an intelligent workload management system, comprising:

an authentication server that generates authentication tokens defining entitlements for a plurality of unique identities across a plurality of authentication domains, wherein the authentication server generates the authentication tokens from federated identity information stored in an identity vault, and wherein the entitlements are derived from single sign-on workload identities for a given user and define various credentials assigned to the given user, an operating system contacts an authentication server to obtain the authentication tokens that define the credentials and permissions on the workload identities;

a discovery engine that discovers a model describing an operational state for an information technology infrastructure and enriches the model with the federated information stored in the identity vault and actual activity monitored for the plurality of unique identities in the information technology infrastructure, wherein the discovery engine is configured to:

discover, from the federated information stored in the identity vault, information that describes one or more physical resources and one or more virtualized resources in the information technology infrastructure, one or more applications and one or more services running in the information technology infrastructure, and dependencies between the physical resources, the virtualized resources, the applications, and the services;

discover information that describes the plurality of unique identities access to the physical resources, the virtualized resources, the applications, and the services in the infrastructure, wherein the discovered access information includes the entitlements defined in the authentication tokens generated at the authentication server and the actual activity monitored for the plurality of unique identities in the infrastructure; and

capture a snapshot of the model of the information technology infrastructure, wherein the snapshot includes the information that describes the physical resources, the virtualized resources, the applications, and the services, the dependencies between the physical resources, the virtualized resources, the applications, and the services, and the discovered access information; and

a management infrastructure that manages the captured snapshot of the infrastructure model, wherein the management infrastructure is configured to:

detect one or more problems or incidents in the information technology infrastructure in response to determining that the captured snapshot of the infrastructure model violates one or more predetermined policies; and

manage one or more remediation workloads in response to detecting the one or more problems or incidents in the information technology infrastructure.

2. A system for discovery enrichment in an intelligent workload management system, comprising:

an identity vault that stores federated information defining entitlements for a plurality of unique identities across a plurality of authentication domains, and wherein the entitlements are derived from single sign-on workload identities for a given user and define various credentials assigned to the given user, an operating system contacts an authentication server to obtain authentication tokens that define credentials and permissions on the workload identities;

an authentication server that generates the authentication tokens defining the entitlements for the plurality of unique identities from the federated information stored in the identity vault;

a discovery engine that discovers a model describing an operational state for an information technology infrastructure and enriches the model with the federated information stored in the identity vault and actual activity monitored for the plurality of unique identities in the information technology infrastructure, wherein the discovery engine is configured to:

discover, from the federated information stored in the identity vault, information that describes one or more physical resources and one or more virtualized resources in the information technology infrastructure;

discover, from the federated information stored in the identity vault, information that describes one or more applications and one or more services running in the information technology infrastructure;

discover, from the federated information stored in the identity vault, information that describes dependencies between the physical resources, the virtualized resources, the applications, and the services discovered in the information technology infrastructure;

discover information that describes the plurality of unique identities access to the physical resources, the virtualized resources, the applications, and the services in the infrastructure, wherein the discovered access information includes the entitlements defined in the authentication tokens generated at the authentication server and the actual activity monitored for the plurality of unique identities in the infrastructure; and

capture a snapshot of the model of the information technology infrastructure, wherein the snapshot includes the information that describes the physical resources, the virtualized resources, the applications, and the services, the dependencies between the physical resources, the virtualized resources, the applications, and the services, and the discovered access information.

3. The system of claim 2 , further comprising a configuration management database configured to persistently store the captured snapshot of the infrastructure model.

4. The system of claim 2 , wherein the authentication tokens include single sign-on authentication tokens that provide portable data abstractions encapsulating the entitlements for the unique identities across the plurality of authentication domains.

5. The system of claim 2 , wherein the discovery engine discovers the information that describes the physical resources and the virtualized resources using one or more of Internet Control Message Protocol pings, Simple Network Management Protocol Gets, Transmission Control Protocol port probes, or agent-based discovery techniques.

6. The system of claim 2 , wherein the discovery engine discovers the information that describes the applications and the services using an application fingerprinting technique that matches one or more artifacts in the discovered information for the physical resources and the virtualized resources to one or more predetermined attributes that uniquely describe the applications and the services.

7. The system of claim 2 , wherein the dependencies describe relationships between one or more of the physical resources that host one or more of the virtualized resources, and wherein the dependencies further describe relationships between one or more of the virtualized resources that host one or more of the applications or one or more of the services.

8. The system of claim 2 , wherein the entitlements defined in the authentication tokens indicate whether the plurality of unique identities are authorized or permitted to interact with one or more of the physical resources, the virtualized resources, the applications, or the services.

9. The system of claim 8 , wherein the snapshot further includes the authentication tokens that indicate whether the plurality of unique identities are authorized or permitted to interact with the physical resources, the virtualized resources, the applications, or the services.

10. The system of claim 9 , further comprising a workload engine configured to manage one or more remediation workloads in response to detecting one or more problems or incidents in the information technology infrastructure.

11. The system of claim 10 , further comprising a management infrastructure configured to detect the one or more problems or incidents in the information technology infrastructure in response to determining that the captured snapshot of the infrastructure model violates one or more predetermined policies.

12. A method for discovery enrichment in an intelligent workload management system, comprising:

storing, in an identity vault, federated information defining entitlements for a plurality of unique identities across a plurality of authentication domains, wherein the entitlements are derived from single sign-on workload identities for a given user and define various credentials assigned to the given user, an operating system contacts an authentication server to obtain authentication tokens that define the credentials and permissions on the workload identities;

generating, at an authentication server, the authentication tokens defining the entitlements for the plurality of unique identities from the federated information stored in the identity vault; and

discovering, by a discovery engine, a model describing an operational state for an information technology infrastructure enriched with the federated information stored in the identity vault and actual activity monitored for the plurality of unique identities in the information technology infrastructure, wherein discovering the model of the information technology infrastructure includes:

discovering, from the federated information stored in the identity vault, information that describes one or more physical resources and one or more virtualized resources in the information technology infrastructure;

discovering, from the federated information stored in the identity vault, information that describes one or more applications and one or more services running in the information technology infrastructure;

discovering, from the federated information stored in the identity vault, information that describes dependencies between the physical resources, the virtualized resources, the applications, and the services discovered in the information technology infrastructure;

discovering information that describes the plurality of unique identities access to the physical resources, the virtualized resources, the applications, and the services in the infrastructure, wherein the discovered access information includes the entitlements defined in the authentication tokens generated at the authentication server and the actual activity monitored for the plurality of unique identities in the infrastructure; and

capturing a snapshot of the model of the information technology infrastructure, wherein the snapshot includes the discovered information that describes the physical resources, the virtualized resources, the applications, and the services, the dependencies between the physical resources, the virtualized resources, the applications, and the services, and the discovered access information.

13. The method of claim 12 , further comprising persistently storing the captured snapshot of the infrastructure model in a configuration management database.

14. The method of claim 12 , wherein the authentication tokens include single sign-on authentication tokens that provide portable data abstractions encapsulating the entitlements for the unique identities across the plurality of authentication domains.

15. The method of claim 12 , wherein the discover engine discovers the information that describes the physical resources and the virtualized resources using one or more of Internet Control Message Protocol pings, Simple Network Management Protocol Gets, Transmission Control Protocol port probes, or agent-based discovery techniques.

16. The method of claim 12 , wherein the discovery engine discovers the information that describes the applications and the services using an application fingerprinting technique that matches one or more artifacts in the discovered information for the physical resources and the virtualized resources to one or more predetermined attributes that uniquely describe the applications and the services.

17. The method of claim 12 , wherein the dependencies describe relationships between one or more of the physical resources that host one or more of the virtualized resources, and wherein the dependencies further describe relationships between one or more of the virtualized resources that host one or more of the applications or one or more of the services.

18. The method of claim 12 , wherein the entitlements defined in the authentication tokens indicate whether the plurality of unique identities are authorized or permitted to interact with one or more of the physical resources, the virtualized resources, the applications, or the services.

19. The method of claim 18 , wherein the snapshot further includes the authentication tokens indicate whether the plurality of unique identities are authorized or permitted to interact with one or more of the physical resources, the virtualized resources, the applications, or the services.

20. The method of claim 12 , further comprising managing one or more remediation workloads in response to detecting one or more problems or incidents in the information technology infrastructure, wherein a management infrastructure detects the one or more problems or incidents in response to determining that the captured snapshot of the infrastructure model violates one or more predetermined policies.

Assignments (13)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →