Delegated Network Management for Firewall Resource Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls lack the necessary resources to provide management services such as log analysis and report generation due to resource constraints, often requiring separate devices and inconvenient manual login procedures for administrators.

Innovation Solution

A delegated network management system that allows a managed device to redirect a client device to a management device for performing management functions, enabling seamless management service provision without requiring administrators to manually log onto separate devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall performs policy enforcement functions, then security protection is improved, but available resources for management services are reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanagement service capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system separates the firewall into two functional components: a policy enforcement module that handles security functions, and a management service module that handles administrative tasks. This segmentation allows each component to specialize in its function without resource conflicts, resolving the contradiction between security protection and management service capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A management service gateway acts as an intermediary between administrators and the firewall. This gateway handles management services externally, allowing the firewall to maintain full security enforcement capabilities while still providing comprehensive management services through the intermediary component

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate devices are used to provide management services not available from the firewall, then management functionality is improved, but operational convenience is reduced

Engineering Contradiction:
Improvemanagement functionalityVSAvoidaccess convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system merges multiple management functionalities into a single unified management service gateway. This gateway consolidates log analysis, report generation, configuration management, and other administrative functions that were previously scattered across separate devices, thereby improving both functionality and operational convenience through consolidation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The management service gateway is designed as a universal platform that can perform multiple management functions across different firewall models and configurations. It provides a single point of access for administrators to perform diverse management tasks, eliminating the need to manually access separate specialized devices while maintaining versatile functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10027556B2Delegated network management services
Publication Date: 2018.07.17 FORTINET INC
  • US10027556B2 patent drawing
  • US10027556B2 patent drawing
  • US10027556B2 patent drawing

AI summary

A method for providing a management function requested by a user that uses a managed device includes establishing a session on a managed device in response to a user logging into an account on the managed device, establishing a delegated management session on a management device, the delegated management session corresponding to the session on the managed device, receiving a management message on the management device, the management message being related to a management function requested by the user, and in response to the received management message, performing the management function using the management device.