Bridgehead Servers Automate Perimeter Network Configuration Replication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual transfer of configuration information from a trusted network to a perimeter network is time-consuming, poses security risks, and is inefficient due to differing security mechanisms, making it desirable to automate this process and ensure communication adaptability in case of device unavailability.

Innovation Solution

A system comprising master servers in the trusted network, edge servers in the perimeter network, and bridgehead servers that use Lightweight Directory Access Protocol (LDAP) to automatically replicate and manage configuration information, establishing communication paths and adapting to changes in server status, allowing for regular and secure information transfer without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual transfer of configuration information is used, then security control is maintained, but time consumption increases and efficiency decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces bridgehead servers as intermediary components that facilitate automatic communication between the trusted network and perimeter network. These bridgehead servers act as mediators that can replicate configuration information automatically, eliminating the need for manual transfers while maintaining security through controlled communication paths established by the bridgehead servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual transfer of configuration information is used, then security mechanisms are respected, but productivity decreases

Engineering Contradiction:
Improvesecurity mechanismsVSAvoidefficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service functionality where the bridgehead servers automatically replicate configuration information from the distributed directory service without requiring administrator intervention. The system monitors its own state and autonomously maintains communication paths, eliminating manual transfer tasks and significantly improving productivity while adhering to security mechanisms through automated authentication and authorization.

Inventive Principle:
Principle #25Self-service

3Productivity

If automatic communication is established, then efficiency improves, but system complexity increases

Engineering Contradiction:
ImproveefficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the communication infrastructure by introducing dedicated bridgehead servers that are separate from both the trusted network servers and perimeter network servers. This segmentation allows the bridgehead servers to handle the complexity of automatic communication and path establishment, isolating this complexity from the rest of the system while maintaining efficiency through automated operation.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If single communication path is used, then simplicity is maintained, but adaptability to server failures decreases

Engineering Contradiction:
ImprovesimplicityVSAvoidadaptability to server failures
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic communication path management where the bridgehead servers continuously monitor the operational status of trusted network servers and perimeter network servers. When failures are detected, the system dynamically redirects communication paths to alternative functional servers, maintaining adaptability while keeping the overall architecture simple through automated detection and response mechanisms.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8726020B2Updating configuration information to a perimeter network
Publication Date: 2014.05.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8726020B2 patent drawing
  • US8726020B2 patent drawing
  • US8726020B2 patent drawing

AI summary

Automatically sending configuration information from a trusted network to a perimeter network. Master servers residing in the trusted network are adapted for administering a distributed directory service containing configuration information. Edge servers residing in the perimeter network are adapted for using a local directory service local to each edge server. Edge-connected bridgehead servers residing in the trusted network are adapted for replicating the configuration information from the trusted network to the perimeter network. Replicating the configuration information to the perimeter network by trusted servers acquiring leases on edge servers is also disclosed.