Blockchain Network Device Patch Management via Multi-Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network device management, there is a need for secure and verifiable updates and configuration changes, particularly in ensuring that only authorized parties can implement these changes to prevent malicious interventions.
Innovation Solution
A blockchain-based method for managing network devices involves determining unresponsiveness, sending patches through intermediary devices with multi-signed transactions, verifying patch safety, and recording transactions on a blockchain to ensure authenticity and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network device management methods are used, then updates and configuration changes can be implemented, but security and verification of authorized changes cannot be ensured
Solution Approach 1:
The patent introduces an intermediary device (blockchain network) that mediates between the management apparatus and network devices. This intermediary ensures secure verification of patch authenticity and authorized application through cryptographic signatures and distributed ledger technology, resolving the security concern without requiring direct trust between all parties.
Solution Approach 2:
The patent replaces traditional mechanical/centralized authorization mechanisms with cryptographic and blockchain-based verification systems. Multi-signed transactions and hash verification mechanisms substitute for conventional access control lists and manual authorization processes, providing enhanced security with automated verification.
2Reliability
If multi-signed transactions and blockchain validation are used, then authorized and verifiable updates are ensured, but the complexity of the management process increases
Solution Approach 1:
The patent implements self-service mechanisms where network devices automatically verify patch authenticity and authorized application through cryptographic verification. The devices autonomously check digital signatures and blockchain validation without requiring manual intervention from administrators, simplifying the operational process while maintaining high verification standards.
Solution Approach 2:
The patent performs preliminary verification actions by validating patch authenticity and authorization status before application. The blockchain network pre-verifies transaction validity and patch integrity in advance, so that when patches are applied, the verification process is already complete, reducing operational complexity during the actual patch deployment.
3Object-affected harmful factors
If patches are sent through intermediary devices with blockchain validation, then unauthorized changes are prevented, but the time required for patch application increases
Solution Approach 1:
The patent performs preliminary validation of patch authenticity and authorization status through blockchain verification before the actual patch application. By completing verification actions in advance and maintaining pre-signed transaction records, the system minimizes time delays during patch deployment while ensuring unauthorized changes cannot occur.
Data Source
AI summary
An apparatus (101) is disclosed for remotely controlling a network device (102). The apparatus comprises means for determining (200) that said network device (102) is unresponsive; means for determining a patch for application at said network device (102) for resolving said unresponsiveness; means for sending (207) said patch to an intermediary device (103) capable of communicating with said network device (102); means for signing (208) a first transaction corresponding to said patch with a blockchain network (104), wherein said first transaction is a multi-signed transaction signed by said apparatus (101) and said intermediary device (103) and wherein said first transaction is indicative of a patch result to be obtained; and means for receiving (218) a message from said intermediary device (103) that said patch has been applied.Also disclosed are a network device, an intermediary device, a blockchain network device and corresponding methods.


