Bridgehead Servers Automate Perimeter Network Configuration Replication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manual transfer of configuration information from a trusted network to a perimeter network is time-consuming, poses security risks, and is inefficient due to differing security mechanisms, making it desirable to automate this process and ensure communication adaptability in case of device unavailability.
Innovation Solution
A system comprising master servers in the trusted network, edge servers in the perimeter network, and bridgehead servers that use Lightweight Directory Access Protocol (LDAP) to automatically replicate and manage configuration information, establishing communication paths and adapting to changes in server status, allowing for regular and secure information transfer without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual transfer of configuration information is used, then security control is maintained, but time consumption increases and efficiency decreases
Solution Approach 1:
The patent introduces bridgehead servers as intermediary components that facilitate automatic communication between the trusted network and perimeter network. These bridgehead servers act as mediators that can replicate configuration information automatically, eliminating the need for manual transfers while maintaining security through controlled communication paths established by the bridgehead servers.
2Reliability
If manual transfer of configuration information is used, then security mechanisms are respected, but productivity decreases
Solution Approach 1:
The patent implements self-service functionality where the bridgehead servers automatically replicate configuration information from the distributed directory service without requiring administrator intervention. The system monitors its own state and autonomously maintains communication paths, eliminating manual transfer tasks and significantly improving productivity while adhering to security mechanisms through automated authentication and authorization.
3Productivity
If automatic communication is established, then efficiency improves, but system complexity increases
Solution Approach 1:
The patent segments the communication infrastructure by introducing dedicated bridgehead servers that are separate from both the trusted network servers and perimeter network servers. This segmentation allows the bridgehead servers to handle the complexity of automatic communication and path establishment, isolating this complexity from the rest of the system while maintaining efficiency through automated operation.
4Device complexity
If single communication path is used, then simplicity is maintained, but adaptability to server failures decreases
Solution Approach 1:
The patent implements dynamic communication path management where the bridgehead servers continuously monitor the operational status of trusted network servers and perimeter network servers. When failures are detected, the system dynamically redirects communication paths to alternative functional servers, maintaining adaptability while keeping the overall architecture simple through automated detection and response mechanisms.
Data Source
AI summary
Automatically sending configuration information from a trusted network to a perimeter network. Master servers residing in the trusted network are adapted for administering a distributed directory service containing configuration information. Edge servers residing in the perimeter network are adapted for using a local directory service local to each edge server. Edge-connected bridgehead servers residing in the trusted network are adapted for replicating the configuration information from the trusted network to the perimeter network. Replicating the configuration information to the perimeter network by trusted servers acquiring leases on edge servers is also disclosed.


