Device-Initiated Network Management Bypassing Security Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed service providers face difficulties in managing remote networks due to security constraints, such as private network addressing and firewalls, which prevent them from retrieving necessary configuration information or issuing commands, and existing protocols like SNMP are insufficient for large, heterogeneous networks, leading to challenges in remote diagnosis and intervention.

Innovation Solution

A device-initiated network management system that allows network elements to periodically evaluate conditions, gather information, and send messages to a management point, enabling secure communication across administrative and security boundaries without direct NMS access, using a management communication program and message agent to initiate management requests and notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional NMS communicates with network elements to retrieve configuration information and issue commands, then network management functionality is provided, but the NMS cannot access network elements in secured private networks due to firewalls and private network addressing

Engineering Contradiction:
ImproveNMS access to network elementsVSAvoidsecurity constraints
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a network element within the private network that acts as an intermediary between the external NMS and internal network elements. This intermediary receives management requests from the NMS, translates them into appropriate internal commands, and returns results, thereby bridging the security boundary without compromising network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of the NMS initiating direct access to network elements (which is blocked by firewalls), the system inverts the approach by having network elements within the private network initiate communication with the NMS. This allows management operations to proceed while maintaining security boundaries, as the initiated communication is permitted by the firewall architecture.

Inventive Principle:
Principle #13The other way round (Inversion)

2Adaptability or versatility

If SNMP is used for sending management requests, then standard protocol communication is established, but firewalls block SNMP requests from outside entities and insufficient information can be retrieved

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidmanagement information retrieval
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the information retrieval process into multiple stages: first using standard SNMP for basic accessibility, then employing additional information gathering mechanisms for detailed configuration data. This segmentation allows the system to retrieve both standard and non-standard management information while maintaining protocol compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network element acting as an intermediary is designed with multi-functionality, supporting both standard SNMP protocols for basic communication and additional proprietary protocols for retrieving extended configuration information. This universal approach enables comprehensive information retrieval while maintaining compatibility with standard network management infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If device sends alarm information to remote management system, then fault notification is provided, but the device may no longer be reachable when alarm occurs, delaying diagnosis and troubleshooting

Engineering Contradiction:
Improvefault diagnosis timeVSAvoiddevice reachability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements preliminary action by having the network element continuously monitor and cache diagnostic information before alarms occur. When an alarm is triggered, the pre-cached information is immediately available for remote analysis, eliminating the need to attempt reconnection to the alarmed device and significantly reducing diagnosis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes continuous feedback loops where network elements regularly report status information and diagnostic data to the management system. This ongoing feedback ensures that when alarms occur, the management system already possesses current diagnostic information, enabling immediate troubleshooting without requiring device reconnection.

Inventive Principle:
Principle #23Feedback

4Reliability

If MSP manages multiple networks from separate secured environments, then security is maintained, but the MSP cannot reach into managed networks to retrieve configuration information or issue commands

Engineering Contradiction:
Improvenetwork securityVSAvoidremote network management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent deploys intermediary network elements within each secured private network that maintain security boundaries while enabling management access. These intermediaries receive authenticated requests from the MSP's management system, perform necessary operations within the secured network, and return results without compromising the security isolation between the MSP and managed networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds a new dimensional layer to network management by introducing a hierarchical structure with intermediary elements. This creates multiple levels of access: the MSP manages intermediaries at one level, while intermediaries manage actual network elements at another level. This dimensional change enables remote management capability while preserving security boundaries through the hierarchical architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7856493B1Method and apparatus providing device-initiated network management
Publication Date: 2010.12.21 CISCO TECHNOLOGY INC
  • US7856493B1 patent drawing
  • US7856493B1 patent drawing
  • US7856493B1 patent drawing

AI summary

A method is disclosed for managing a network entity that is initiated by the network entity, the method comprising the computer-implemented steps performed at the network entity of monitoring the network entity; periodically evaluating one or more specified conditions at the managed network entity; when one or more of the specified conditions are satisfied, then gathering specified information from the managed network entity, preparing a message that includes the specified information and the specified conditions that were satisfied, and sending the message to a management point.