Alarm Identification Component Augments Network Alarms for NAT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed Service Providers (MSPs) face challenges in accurately identifying the device associated with alarms in computer networks, especially when private IP addresses are used, as these addresses can overlap and Network Address Translation (NAT) complicates unique device identification, leading to resource-intensive maintenance and costly information management.

Innovation Solution

An alarm system that includes an Alarm Identification Component (AIC) which augments alarms with identification information, such as site and device identity, geographical data, and network details, allowing the MSP to accurately determine the originating device even with NAT or private IP addressing schemes, by deploying AIC within the network or at the NOC.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT is used to allow multiple devices to share a single public IP address, then network address efficiency is improved, but device identification accuracy deteriorates

Engineering Contradiction:
Improvenetwork address efficiencyVSAvoiddevice identification accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The system segments the identification task by separating public IP address routing from private device identification. The AIC component divides the alarm processing workflow into stages: initial public IP reception, then augmented identification using private IP addresses and device-specific identifiers that are inserted into the alarm data stream, allowing precise device identification while maintaining NAT's address sharing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Alarm Identification Component (AIC) acts as an intermediary between the NAT network and the MSP's alarm processing system. The AIC receives alarms containing public IP addresses, augments them with additional identification information (private IP addresses, device identifiers), and forwards the enriched alarms to the MSP, thereby resolving the identification ambiguity created by NAT.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the MSP maintains a repository of private IP addresses for each customer using NAT, then device identification accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service by having the AIC automatically generate and insert appropriate identification information into alarm data streams without requiring manual MSP intervention. The AIC autonomously determines which private IP address or device identifier to insert based on the alarm source, eliminating the need for the MSP to manually maintain complex repositories of customer IP addressing schemes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The AIC performs preliminary action by pre-augmenting alarm data with identification information before the alarm reaches the MSP. This advance preparation includes inserting private IP addresses, device identifiers, or other distinguishing information into the alarm stream, so that the MSP receives fully identified alarms without needing to perform complex lookups or maintain detailed IP repositories.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the MSP executes a dedicated alarm application instance at the NOC for each customer site, then device identification accuracy is improved, but resource consumption increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The AIC implements a universal, multi-functional solution that handles identification for all customer sites through a single component or shared system. Rather than deploying separate dedicated alarm application instances at each customer site, the AIC provides centralized alarm augmentation services that work across multiple customers, reducing overall resource consumption while maintaining accurate device identification for all sites.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If the customer site keeps the MSP informed of current IP addressing schemes and device identities, then device identification accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidease of operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The AIC implements self-service by automatically obtaining and using identification information from the customer's network infrastructure without requiring manual updates or customer intervention. The AIC leverages existing network elements (routers, switches, or other network devices) that already possess knowledge of private IP addressing and device identifiers, eliminating the operational burden of keeping the MSP informed of IP scheme changes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7502847B2Method of providing views of a managed network that uses network address translation
Publication Date: 2009.03.10 CISCO TECHNOLOGY INC
  • US7502847B2 patent drawing
  • US7502847B2 patent drawing
  • US7502847B2 patent drawing

AI summary

A method and mechanism for communicating an alarm in a computer network is provided. An alarm system enables a MSP to accurately determine which device within a computer network is associated to a received alarm. Initially, an event is detected on a device on the computer network. An alarm is propagated to an alarm identification component. The alarm identification component augmenting the alarm with identification information to result in creating an augmented alarm. Thereafter, the augmented alarm is transmitted to a network operations center for the computer network. The network operations center may process the alarm using the additional information in the alarm. Accordingly, using the augmented alarm, the MSP is able to accurately determine the identity of the originating device, regardless of whether the customer site of the originating device uses NAT or a private IP addressing scheme.