Network Device Configuration Automation via Protocol Relationships

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of network device configuration leads to manual, time-consuming, and error-prone processes, often resulting in misconfiguration, which can expose networks to malicious activities and sub-optimal performance, particularly during events like DDOS attacks.

Innovation Solution

A method and system that automate network device configuration using protocol-specified relationships to generate and program granular filtering rules, allowing network administrators to configure devices without specifying specific source or destination addresses, and enabling auto-update mechanisms to propagate changes efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration methods are used to configure network devices, then network administrators can update device configurations, but the process becomes time-consuming and error-prone

Engineering Contradiction:
ImproveConfiguration processVSAvoidConfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service through automated configuration generation. The rule generator automatically creates configuration rules based on protocol specifications and network device relationships, eliminating the need for manual configuration by network administrators. The system serves itself by autonomously updating configurations when network changes are detected.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-defining protocol specifications and relationship templates before configuration is needed. These pre-established protocols and templates enable rapid automatic configuration generation when network changes occur, avoiding time-consuming manual setup.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual configuration methods are used to configure network devices, then network administrators can update device configurations, but errors and misconfigurations occur

Engineering Contradiction:
ImproveConfiguration processVSAvoidConfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The automated system eliminates human error by self-generating configurations based on predefined protocols. The rule generator autonomously creates accurate configuration rules without manual intervention, ensuring consistent and error-free device setup.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where configuration rules are automatically generated, applied, and monitored. When network changes are detected or misconfigurations occur, the system receives feedback and automatically adjusts configurations to maintain reliability.

Inventive Principle:
Principle #23Feedback

3Reliability

If granular filtering rules are generated and programmed into network devices, then security against malicious traffic is enhanced, but configuration overhead increases

Engineering Contradiction:
ImproveNetwork securityVSAvoidConfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses universal protocol specifications that apply across multiple network devices and scenarios. A single protocol definition can generate configuration rules for numerous devices, reducing overall configuration complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The configuration process is segmented into distinct components: protocol specifications, relationship templates, rule generation, and device programming. This segmentation allows each component to be independently managed and reused, reducing the perceived complexity of the overall system.

Inventive Principle:
Principle #1Segmentation

4Reliability

If automated rule generation is implemented using protocol-specified relationships, then configuration errors are reduced, but system complexity increases

Engineering Contradiction:
ImproveConfiguration accuracyVSAvoidSystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The rule generator acts as an intermediary between protocol specifications and device configurations. It translates high-level protocol relationships into detailed configuration rules, shielding network administrators from system complexity while ensuring accurate configuration generation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses template copying where standardized protocol relationship templates are replicated and adapted for different network devices. This copying mechanism simplifies the system architecture by reusing proven configurations rather than creating unique configurations for each device.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11838178B2System and method for managing a network device
Publication Date: 2023.12.05 ARISTA NETWORKS INC
  • US11838178B2 patent drawing
  • US11838178B2 patent drawing
  • US11838178B2 patent drawing

AI summary

In general, embodiments described herein relate to methods and systems for automating the configuration of network devices. More specifically, embodiments of the invention relate to using configuration commands that specify protocol-specified relationships in order to generate granular (or specific) filtering rules (also referred to as rules). The rules are subsequently programmed into the network device.