Online Network Device Configuration Validation via Shadow Interpreter

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for validating network device configuration profiles are costly, prone to errors, and often require offline testing using duplicate or simulated environments, which do not validate configurations on the actual hardware, leading to potential misconfigurations and increased complexity.

Innovation Solution

Implementing an online validation method that creates an isolated validation environment on the network device, allowing configuration profiles to be validated using the actual hardware and software while the device remains operational, reducing the need for duplicate test environments and simulators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If offline validation using duplicate or simulated environments is used, then configuration validation can be performed, but the validation does not occur on actual hardware leading to potential misconfigurations and increased complexity

Engineering Contradiction:
Improveconfiguration validation accuracyVSAvoidvalidation environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the network device that replicates its configuration and operational state. This virtual instance allows validation to be performed on actual hardware characteristics while maintaining isolation, thus achieving accurate validation without the complexity of duplicate physical environments or imperfect simulators.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a validation environment that acts as an intermediary between the configuration validation process and the actual network device. This intermediary layer enables validation to occur with access to real hardware characteristics while preventing direct impact on the operational device, resolving the contradiction between validation accuracy and system reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If configuration validation is performed offline using test environments, then validation can be completed, but it requires duplicate test hardware and separate software components increasing cost and complexity

Engineering Contradiction:
Improveconfiguration validation capabilityVSAvoidvalidation setup cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a validation environment that can validate configurations for multiple different network device types using a single unified system. The virtualization approach allows the same validation infrastructure to adapt to various device architectures, eliminating the need for separate test environments for each device type and reducing overall validation setup cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of requiring duplicate physical hardware for each device type to be validated, the patent creates virtual copies that can be instantiated as needed. This approach eliminates the need for expensive duplicate test hardware while maintaining the ability to validate on actual hardware characteristics.

Inventive Principle:
Principle #26Copying

3Reliability

If traditional validation methods are used, then configuration can be validated, but the process is tedious requiring line-by-line verification increasing time consumption

Engineering Contradiction:
Improveconfiguration validation thoroughnessVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the manual, mechanical process of line-by-line configuration verification with an automated validation system. The virtualized environment automatically executes validation routines against the configuration, substituting human manual checking with automated computational validation that is both more thorough and faster.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The validation system performs self-verification by automatically testing configurations within the virtual environment without requiring external manual intervention for each validation step. The system autonomously identifies potential misconfigurations and validates repairs, eliminating the tedious manual line-by-line verification process.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If configuration validation is performed on operational devices, then real hardware validation is achieved, but it risks causing misconfigurations and network disruption

Engineering Contradiction:
Improvevalidation accuracy on actual hardwareVSAvoidnetwork disruption risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent segments the validation process from the operational network by creating an isolated virtual environment. This segmentation allows validation to occur on actual hardware characteristics while preventing any harmful effects from propagating to the operational network, thus achieving both accurate validation and network protection simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtualized validation environment serves as an intermediary buffer between the validation process and the operational network. It enables real hardware validation while absorbing or isolating any potential misconfigurations, preventing them from causing network disruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11249979B2Systems and methods for live, on-device configuration validation
Publication Date: 2022.02.15 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11249979B2 patent drawing
  • US11249979B2 patent drawing
  • US11249979B2 patent drawing

AI summary

Embodiments of the present disclosure provide systems and methods for performing network device configuration validation online. A second instance of the command process (a shadow interpreter) can be run within a isolated validation environment on a network device that is active on a network. A copy of the configuration database on the network device is associated with the isolated validation environment. The validation handler erases the currently running configuration commands within the validation copy of the configuration database, and enters each new configuration command through the shadow interpreter to validate the new configuration commands on the network device without impacting the current functioning of the network device. After all the new configuration commands are entered, the validation report generates a report identifying the validation status for each command.