Automated Network Device Deployment via Registrar Bootstrap

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying network devices is challenging due to the need for complex configuration and high user knowledge, especially in corporate environments where rapid and secure setup is required, often involving manual configuration that can lead to errors and increased costs due to changing policies.

Innovation Solution

A secure deployment method using a registrar to establish a secure introduction connection, providing bootstrap configuration data for a secure management connection, allowing user-specific configuration and security policies to be implemented automatically, enabling secure and dynamic management of network devices without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration is used to ensure secure network connections, then configuration accuracy is improved, but deployment time and cost increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring network devices with template-based configurations before deployment. The system stores multiple configuration templates that can be automatically applied to devices, eliminating the need for manual post-deployment configuration and reducing deployment time while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating and storing configuration templates that can be replicated across multiple network devices. Instead of manually configuring each device individually, the system copies proven secure configurations from templates, ensuring consistency and accuracy while significantly reducing the time and resources required for deployment.

Inventive Principle:
Principle #26Copying

2Reliability

If manual configuration is performed to handle changing corporate policies, then configuration accuracy is improved, but resource costs increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidresource costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies dynamics by implementing a system where configuration templates can be dynamically updated to reflect changing corporate policies. When policies change, the templates are updated centrally, and the changes are automatically propagated to deployed devices, eliminating the need for manual reconfiguration and reducing resource costs while maintaining accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses copying by replicating updated configuration templates across multiple devices automatically. When corporate policies change, the updated template is copied to all relevant devices, ensuring consistent and accurate configuration updates without requiring manual intervention, thereby reducing resource costs.

Inventive Principle:
Principle #26Copying

3Productivity

If automated deployment is used to reduce manual labor, then deployment speed is improved, but configuration accuracy deteriorates

Engineering Contradiction:
Improvedeployment speedVSAvoidconfiguration accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses copying by automatically replicating pre-validated configuration templates to multiple network devices during deployment. This automated copying process ensures that each device receives an identical, proven secure configuration, maintaining high accuracy while achieving rapid deployment across numerous devices simultaneously.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies parameter changes by allowing configuration templates to be parameterized with variables that can be automatically adjusted based on device-specific information. This enables automated deployment to adapt configurations to individual devices while maintaining the core secure structure, ensuring both speed and accuracy.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If user involvement is increased to handle complex configuration tasks, then configuration accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidease of deployment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses copying by automatically applying pre-configured templates to network devices without requiring user intervention. Users simply initiate the deployment process, and the system automatically copies the appropriate configuration template to the device, eliminating the need for users to understand complex configuration tasks while ensuring accurate, secure configurations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies self-service by enabling the system to automatically perform configuration tasks without user involvement. The automated deployment system selects and applies appropriate templates, manages configuration updates, and handles policy changes independently, making the process easy for users while maintaining high configuration accuracy through proven templates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7748035B2Approach for securely deploying network devices
Publication Date: 2010.06.29 CISCO TECHNOLOGY INC
  • US7748035B2 patent drawing
  • US7748035B2 patent drawing
  • US7748035B2 patent drawing

AI summary

According to an approach for securely deploying and configuring network devices, a secure introduction connection is established between a network device being deployed and a registrar. The secure introduction connection may conform to a secure communications protocol, such as HTTPS. The registrar provides bootstrap configuration data to the network device over the secure introduction connection. The bootstrap configuration data is used to establish a secure management connection between the network device and a secure management gateway. The secure management connection may conform to a secure communications protocol, such as IPsec or HTTPS. The secure management gateway provides user-specific configuration data and security policy data to the network device over the secure management connection. The user-specific configuration data and policy data are used to establish a secure data connection, such as a Dynamic Multipoint Virtual Private Network (DMVPN) connection, between the network device and the secure data gateway.