Secured Network File Privilege Propagation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In secure networks, particularly government networks, updating or changing configurations on remote devices is time-consuming and expensive due to the need to avoid exposing unprotected ports and altering security settings, which is challenging with existing socket-based systems and firewalls.
Innovation Solution
A system and method for file synchronization within a secured network that propagates a file privilege file through the network without altering security settings, using a stateless protocol to update files on devices while maintaining security through authentication mechanisms like passwords and public keys, allowing administrators to manage access and updates without exposing vulnerable ports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If socket-based connection is used for file transfer, then communication between client and server is enabled, but unprotected ports are exposed creating security breaches
Solution Approach 1:
The patent introduces a file server as an intermediary component that receives files from external sources and makes them available to network devices through a controlled interface. This mediator enables file transfer functionality without requiring client devices to directly connect to external sources, thus avoiding port exposure while maintaining file access capability
Solution Approach 2:
The patent implements a file copying mechanism where files are transferred from the file server to local storage on network devices. This copying approach allows devices to obtain updated files without establishing persistent connections or exposing ports, as the transfer is initiated by the device requesting the file rather than an external source pushing it through an open port
2Reliability
If security settings are locked down to prevent breaches, then network security is maintained, but manual updates require physical dispatch increasing time and cost
Solution Approach 1:
The patent implements a self-service update mechanism where network devices automatically check for updated files on the file server and initiate downloads as needed. This eliminates the need for manual intervention or physical dispatch to update devices, while the locked-down security settings remain in place. The system serves itself by allowing devices to autonomously retrieve updates through the secure file server interface
Solution Approach 2:
The patent pre-configures network devices with the location and identification of the file server during initial setup. This preliminary action enables devices to know where to find updates without requiring subsequent configuration changes or manual intervention. The devices are prepared in advance to autonomously seek and retrieve updated files when needed
3Object-affected harmful factors
If ports are kept protected to maintain security, then security breaches are prevented, but file distribution requires manual intervention
Solution Approach 1:
The patent creates a universal file server interface that serves multiple functions: storing files, distributing updates to multiple devices, and managing file versions. This single multi-functional component enables automated file distribution across the entire network without requiring individual port configurations on each device, thus maintaining security while dramatically improving distribution efficiency
Data Source
AI summary
A system and method of distributing a file maintained on a first device located at the top tier of a secured network having at least a second device at a lower tier, without needing to change security parameters of the secured network, is disclosed. Network administrators may access the top tier of the network, may add files into the system, and may generate a file privilege file. The file privilege file can include configuration information for a computer on a tier and may include information about files accessible to a computer on a specific tier. The network propagates the file privilege file from the first device through intermediate devices and onto the second device. The second device may then receive a file authorized from the first device via a connection in the secured network. The second device may also propagate files up to the first device.


