Dynamic Key Server Discovery for Automated Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key management systems require manual configuration of key server lists on group members, which is burdensome and inefficient, especially when key management servers are added or retired, as administrators must manually update the lists across multiple devices.

Innovation Solution

A discovery server dynamically provides an ordered list of key servers to group members through discovery messages, eliminating the need for manual configuration by automatically updating the lists when changes occur, such as the addition or removal of key servers, and allowing for load balancing by distributing different lists to different subgroups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of key server lists is used on each group member, then system reliability is maintained through configured backups, but administrative burden and time consumption increase significantly

Engineering Contradiction:
Improvesystem reliabilityVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key management system performs self-configuration by automatically discovering available key servers and generating ordered lists without administrator intervention. The system monitors itself for changes in key server availability and dynamically updates group member configurations, eliminating manual administrative work while maintaining reliability through automated backup management

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where key management servers report their status and availability to the discovery mechanism. This feedback enables automatic detection of key server changes, triggering dynamic updates to ordered lists on group members, ensuring reliability is maintained through real-time adaptation without manual intervention

Inventive Principle:
Principle #23Feedback

2Loss of information

If manual updates of key server lists are performed when servers are added or retired, then system configuration remains accurate, but administrative workload increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidadministration efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The key server list configuration transitions from static manual updates to dynamic automatic discovery. The system continuously monitors the key management infrastructure, automatically detects when servers are added or retired, and dynamically regenerates ordered lists for all group members, ensuring configuration accuracy without administrative intervention

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The discovery mechanism performs preliminary actions by proactively scanning for available key servers and pre-generating updated ordered lists before administrative needs arise. This preliminary discovery and configuration preparation eliminates reactive manual updates, maintaining accuracy while improving administrative efficiency

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple key management servers are deployed for load balancing, then system efficiency improves, but configuration complexity increases

Engineering Contradiction:
Improvesystem efficiencyVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The discovery server implements a universal configuration mechanism that serves multiple functions: it discovers key servers, generates ordered lists, distributes configurations to all group members, and monitors for changes. This single multi-functional system handles the complexity of multiple key management servers uniformly, improving efficiency while reducing overall configuration complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The discovery server acts as an intermediary between the plurality of key management servers and the group members. It abstracts the complexity of multiple servers by generating and distributing simplified ordered lists, enabling load balancing across multiple servers without requiring each group member to directly manage the complexity of the entire key management infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8266286B2Dynamic key management server discovery
Publication Date: 2012.09.11 CISCO TECHNOLOGY INC
  • US8266286B2 patent drawing
  • US8266286B2 patent drawing
  • US8266286B2 patent drawing

AI summary

Various systems and method are disclosed for automatically disseminating key server contact information in a network. For example, one method (e.g., performed by a discovery server) involves generating a discovery message that includes at least one list of one or more key servers and then sending that discovery message to one or more members of a key management protocol group. Each list of key servers can include contact information for one or more key servers and indicate the priority of each key server relative to other key servers within the list.