Network Automation System Policy Validation for Manual Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network automation systems fail to manage both manual and automated changes effectively, leading to incomplete assurance and compliance with authorization levels and policies, as manual changes often circumvent the system's protections.

Innovation Solution

A network automation system that models and orchestrates both manual and automated changes, includes a policy module for verification, a device proxy for user access, and a workflow process and approval engine to ensure compliance, while also allowing for emergency overrides.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual changes are implemented directly by users, then ease of operation is improved, but reliability and compliance deteriorate because manual changes circumvent system protections

Engineering Contradiction:
Improveease of making manual changesVSAvoidcompliance with policies and authorization levels
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device proxy acts as an intermediary between users and network devices. It intercepts manual change commands, validates them against policies and authorization levels, and only permits changes that comply with organizational rules. This mediator approach maintains user operational freedom while ensuring reliability and compliance through automated validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network automation system is used for all changes, then reliability and compliance are improved, but device complexity and ease of operation worsen due to system rigidity

Engineering Contradiction:
Improveassured compliance with policiesVSAvoidflexibility for expert engineer changes
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts its control mechanisms based on the type of change being implemented. For automated changes, full policy validation and approval workflows are enforced. For manual changes by expert engineers, the system provides guided validation with optional emergency override capabilities. This dynamic approach maintains reliability while accommodating operational flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes its validation parameters based on user role and change type. Expert engineers have access to emergency override parameters that allow them to bypass certain validations when necessary, while still maintaining audit trails. This parameter adjustment enables the system to be both strict for routine operations and flexible for expert-driven changes.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If both manual and automated changes are managed separately, then ease of operation is improved, but reliability deteriorates because manual changes are not tracked

Engineering Contradiction:
Improveindependence of manual and automated processesVSAvoidprocess assurance for manual changes
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges the management of manual and automated changes into a unified framework. The device proxy intercepts and validates both manual user commands and automated system commands through the same policy validation mechanisms. This unified approach ensures that all changes, regardless of origin, are tracked, validated, and recorded in a centralized manner, providing comprehensive process assurance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8676931B1Methods for managing manual changes to network infrastructures through automated systems
Publication Date: 2014.03.18 VALTRUS INNOVATIONS LTD
  • US8676931B1 patent drawing
  • US8676931B1 patent drawing
  • US8676931B1 patent drawing

AI summary

Network automation systems, and methods of implementing planned changes to a network infrastructure are provided. A network automation system includes software configured to model a manual change of the planned change and identify a conflict between the manual change and another change of the planned change. The system also includes a policy module configured to verify that the changes of the planned change conform to a policy. The system further includes a device proxy configured to allow a user to implement the manual change. An exemplary method for implementing the planned changes includes modeling a manual change of the planned change, checking for a conflict between the manual change and another change, and implementing the planned change. The method can also include verifying that the manual change complies with a policy.