Network Mediator for Firewall-Traversal Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network device management systems are limited by passive SNMP agents that cannot initiate communication, making it difficult to manage devices in private or local networks across Internet-based firewalls, and changing legacy architecture to proactive agents is impractical.

Innovation Solution

Implementing network mediators as proactive agents that communicate with device management servers through firewalls, receiving policies to configure and manage network devices, and transmitting instructions and responses using SNMP messages, while establishing secure connections and authenticating with the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive SNMP agents are used in network devices, then the legacy architecture is maintained and devices can respond to manager queries, but the agents cannot initiate communication proactively and cannot be managed across Internet-based firewalls

Engineering Contradiction:
Improvedevice management capabilityVSAvoidcommunication initiative
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a mediator component that acts as an intermediary between the passive SNMP agent and the management system. This mediator, implemented as a gateway or proxy server, captures SNMP traffic and performs translation between SNMP protocols and web-based protocols (HTTP/HTTPS), enabling proactive management capabilities while maintaining compatibility with existing passive agents and firewall architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the architecture is changed to implement proactive agents, then devices can initiate communication and be managed across firewalls, but it would require years of development efforts and may be virtually impossible in some networks

Engineering Contradiction:
Improveproactive communication capabilityVSAvoidarchitecture modification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the system into three distinct components: the existing passive SNMP agent in the network device, the new mediator gateway/proxy server that handles protocol translation and proactive initiation, and the management system. This segmentation allows the proactive capabilities to be introduced without modifying the legacy SNMP agents or the core management system architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mediator serves as an intermediary layer that bridges the gap between legacy SNMP infrastructure and modern web-based management protocols, enabling proactive communication without requiring changes to existing devices or systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If managers are placed in public networks, then they can access network devices, but they are unable to communicate with devices in private or local networks through Internet-based firewalls

Engineering Contradiction:
Improveremote management accessVSAvoidfirewall blocking
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The mediator gateway is positioned within the private network behind the firewall, acting as an intermediary that receives management requests from public network managers and translates them into appropriate SNMP communications with local devices, thereby bypassing firewall restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the communication protocol parameters from traditional SNMP to web-based protocols (HTTP/HTTPS) for the manager-to-gateway communication, allowing traversal through firewalls that typically block direct SNMP access to private networks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11456920B2Mechanisms for cloud-based configuration and management of network devices using network mediators implemented in the network devices
Publication Date: 2022.09.27 RICOH CO LTD
  • US11456920B2 patent drawing
  • US11456920B2 patent drawing
  • US11456920B2 patent drawing

AI summary

An improved method for configuring and managing network devices using network mediators is provided. The improved method comprises receiving, at a network mediator executing on a network device, from a device management server, one or more policies for configuring or managing the network device. For each policy from the one or more policies: the network mediator determines, based on the policy, one or more instructions for configuring or managing the network device, and transmits the instructions to the network device. Upon receiving, from the network device, a response to the instructions, the network mediator determines whether the response satisfies one or more conditions set forth in the policy. In response to determining that the response satisfies the conditions set forth in the policy, the network mediator generates a message based on the response, and transmits the message to the device management server.