Device-Initiated Network Management Bypassing Security Boundaries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managed service providers face difficulties in managing remote networks due to security constraints, such as private network addressing and firewalls, which prevent them from retrieving necessary configuration information or issuing commands, and existing protocols like SNMP are insufficient for large, heterogeneous networks, leading to challenges in remote diagnosis and intervention.
Innovation Solution
A device-initiated network management system that allows network elements to periodically evaluate conditions, gather information, and send messages to a management point, enabling secure communication across administrative and security boundaries without direct NMS access, using a management communication program and message agent to initiate management requests and notifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional NMS communicates with network elements to retrieve configuration information and issue commands, then network management functionality is provided, but the NMS cannot access network elements in secured private networks due to firewalls and private network addressing
Solution Approach 1:
The patent introduces a network element within the private network that acts as an intermediary between the external NMS and internal network elements. This intermediary receives management requests from the NMS, translates them into appropriate internal commands, and returns results, thereby bridging the security boundary without compromising network security.
Solution Approach 2:
Instead of the NMS initiating direct access to network elements (which is blocked by firewalls), the system inverts the approach by having network elements within the private network initiate communication with the NMS. This allows management operations to proceed while maintaining security boundaries, as the initiated communication is permitted by the firewall architecture.
2Adaptability or versatility
If SNMP is used for sending management requests, then standard protocol communication is established, but firewalls block SNMP requests from outside entities and insufficient information can be retrieved
Solution Approach 1:
The patent segments the information retrieval process into multiple stages: first using standard SNMP for basic accessibility, then employing additional information gathering mechanisms for detailed configuration data. This segmentation allows the system to retrieve both standard and non-standard management information while maintaining protocol compatibility.
Solution Approach 2:
The network element acting as an intermediary is designed with multi-functionality, supporting both standard SNMP protocols for basic communication and additional proprietary protocols for retrieving extended configuration information. This universal approach enables comprehensive information retrieval while maintaining compatibility with standard network management infrastructure.
3Loss of time
If device sends alarm information to remote management system, then fault notification is provided, but the device may no longer be reachable when alarm occurs, delaying diagnosis and troubleshooting
Solution Approach 1:
The patent implements preliminary action by having the network element continuously monitor and cache diagnostic information before alarms occur. When an alarm is triggered, the pre-cached information is immediately available for remote analysis, eliminating the need to attempt reconnection to the alarmed device and significantly reducing diagnosis time.
Solution Approach 2:
The system establishes continuous feedback loops where network elements regularly report status information and diagnostic data to the management system. This ongoing feedback ensures that when alarms occur, the management system already possesses current diagnostic information, enabling immediate troubleshooting without requiring device reconnection.
4Reliability
If MSP manages multiple networks from separate secured environments, then security is maintained, but the MSP cannot reach into managed networks to retrieve configuration information or issue commands
Solution Approach 1:
The patent deploys intermediary network elements within each secured private network that maintain security boundaries while enabling management access. These intermediaries receive authenticated requests from the MSP's management system, perform necessary operations within the secured network, and return results without compromising the security isolation between the MSP and managed networks.
Solution Approach 2:
The system adds a new dimensional layer to network management by introducing a hierarchical structure with intermediary elements. This creates multiple levels of access: the MSP manages intermediaries at one level, while intermediaries manage actual network elements at another level. This dimensional change enables remote management capability while preserving security boundaries through the hierarchical architecture.
Data Source
AI summary
A method is disclosed for managing a network entity that is initiated by the network entity, the method comprising the computer-implemented steps performed at the network entity of monitoring the network entity; periodically evaluating one or more specified conditions at the managed network entity; when one or more of the specified conditions are satisfied, then gathering specified information from the managed network entity, preparing a message that includes the specified information and the specified conditions that were satisfied, and sending the message to a management point.


