Network Device Scripting via Object Virtual Machine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data network systems do not allow clients to download and execute their own software or scripts on network devices, limiting service providers' ability to offer customized services and clients' control over their network resources.

Innovation Solution

A method and system that enable users to program network devices with user-defined instruction scripts through an object virtual machine, allowing clients to configure and control network resources by generating user-defined objects based on received scripts and configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If clients are allowed to download and execute their own software on network devices, then service customization and client control are improved, but system security and stability may deteriorate

Engineering Contradiction:
Improveservice customizationVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a service gateway as an intermediary component between clients and network devices. The service gateway receives service definitions from clients, validates them, and then deploys approved service definitions to network devices. This intermediary architecture allows client customization while maintaining system stability through centralized control and validation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If clients can configure network resources directly, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveclient controlVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the network system into distinct functional components: service definition clients, service gateways, and network devices. Each component has a specific responsibility - clients create service definitions, gateways validate and deploy them, and devices execute them. This segmentation simplifies operation for clients while distributing complexity across the architecture rather than concentrating it in individual devices.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If user-defined scripts are deployed to network devices, then adaptability is improved, but security risks increase

Engineering Contradiction:
Improveservice flexibilityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action through the service gateway's validation mechanism. Before deploying user-defined service definitions to network devices, the service gateway validates them against security policies and system requirements. This pre-validation prevents potentially harmful scripts from being deployed, thereby preventing security threats before they can materialize while still allowing flexible service deployment.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10749904B2Programming a data network device using user defined scripts with licenses
Publication Date: 2020.08.18 A10 NETWORKS INC
  • US10749904B2 patent drawing
  • US10749904B2 patent drawing
  • US10749904B2 patent drawing

AI summary

Provided are methods and systems for configuring a network device with user-defined instruction scripts. The method may commence with receiving a request for a network session between a client device and a server. The method may further include receiving a user-defined class and a user-defined object configuration. The user-defined class and the user-defined object configuration may include the user-defined instruction scripts provided by a user of the client device. The method may further include instructing an object virtual machine to generate at least one user-defined object based on the user-defined class and the user-defined object configuration. The method may continue with instructing an object virtual machine to generate at least one user-defined object based on the user-defined class and the user-defined object configuration.