Secured Network File Privilege Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In secure networks, particularly government networks, updating or changing configurations on remote devices is time-consuming and expensive due to the need to avoid exposing unprotected ports and altering security settings, which is challenging with existing socket-based systems and firewalls.

Innovation Solution

A system and method for file synchronization within a secured network that propagates a file privilege file through the network without altering security settings, using a stateless protocol to update files on devices while maintaining security through authentication mechanisms like passwords and public keys, allowing administrators to manage access and updates without exposing vulnerable ports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If socket-based connection is used for file transfer, then communication between client and server is enabled, but unprotected ports are exposed creating security breaches

Engineering Contradiction:
Improvefile transfer capabilityVSAvoidsecurity breach
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a file server as an intermediary component that receives files from external sources and makes them available to network devices through a controlled interface. This mediator enables file transfer functionality without requiring client devices to directly connect to external sources, thus avoiding port exposure while maintaining file access capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a file copying mechanism where files are transferred from the file server to local storage on network devices. This copying approach allows devices to obtain updated files without establishing persistent connections or exposing ports, as the transfer is initiated by the device requesting the file rather than an external source pushing it through an open port

Inventive Principle:
Principle #26Copying

2Reliability

If security settings are locked down to prevent breaches, then network security is maintained, but manual updates require physical dispatch increasing time and cost

Engineering Contradiction:
Improvenetwork securityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service update mechanism where network devices automatically check for updated files on the file server and initiate downloads as needed. This eliminates the need for manual intervention or physical dispatch to update devices, while the locked-down security settings remain in place. The system serves itself by allowing devices to autonomously retrieve updates through the secure file server interface

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures network devices with the location and identification of the file server during initial setup. This preliminary action enables devices to know where to find updates without requiring subsequent configuration changes or manual intervention. The devices are prepared in advance to autonomously seek and retrieve updated files when needed

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If ports are kept protected to maintain security, then security breaches are prevented, but file distribution requires manual intervention

Engineering Contradiction:
Improvesecurity protectionVSAvoidfile distribution efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent creates a universal file server interface that serves multiple functions: storing files, distributing updates to multiple devices, and managing file versions. This single multi-functional component enables automated file distribution across the entire network without requiring individual port configurations on each device, thus maintaining security while dramatically improving distribution efficiency

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8739300B2System and method for transmission of files within a secured network
Publication Date: 2014.05.27 INTERGRAPH CORP
  • US8739300B2 patent drawing
  • US8739300B2 patent drawing
  • US8739300B2 patent drawing

AI summary

A system and method of distributing a file maintained on a first device located at the top tier of a secured network having at least a second device at a lower tier, without needing to change security parameters of the secured network, is disclosed. Network administrators may access the top tier of the network, may add files into the system, and may generate a file privilege file. The file privilege file can include configuration information for a computer on a tier and may include information about files accessible to a computer on a specific tier. The network propagates the file privilege file from the first device through intermediate devices and onto the second device. The second device may then receive a file authorized from the first device via a connection in the secured network. The second device may also propagate files up to the first device.