Network Model Version Management for Supervision Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network supervision models lack the ability to manage multiple representations of a network, ensure secure transitions between model versions, and account for evolving network configurations and security rules, leading to potential data loss and service disruptions.

Innovation Solution

The solution involves defining network models that allow for multiple representations, enabling simultaneous exploitation of different instances, and providing methods for modifying and duplicating models while preserving security information and calculation results, ensuring continuity and uniqueness of the network supervision process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single representation of monitoring models is used, then model management becomes simpler, but the risk of data loss during version failover increases and service continuity cannot be ensured

Engineering Contradiction:
Improvemodel management complexityVSAvoidservice continuity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the monitoring model into multiple versions (current version and target version) that can coexist. The model is divided into distinct representational layers including model definition, model version, and model instance, allowing parallel management of multiple versions without interference, thus reducing data loss risk while maintaining service continuity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary validation and verification steps before model version failover. The target version is validated in advance through syntax checks, semantic validation, and consistency verification. This preliminary action ensures the target version is ready for failover, reducing the risk of service disruption while maintaining manageable complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple representations of monitoring models are maintained, then service continuity and data security are improved, but model management complexity increases

Engineering Contradiction:
Improveservice continuityVSAvoidmodel management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal model management framework that handles multiple model representations through standardized operations. The model instance serves as a universal container that can represent different versions and configurations. This multi-functional approach allows the system to manage multiple representations through a unified interface, reducing the perceived complexity while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces model instances as intermediary objects between model definitions and actual monitoring operations. These instances act as mediators that abstract the complexity of managing multiple model versions, allowing the system to switch between representations without directly manipulating the underlying model structures, thus maintaining service continuity while simplifying management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If model version failover procedures include numerous safeguards, then data loss is prevented, but the time and complexity of model updates increase

Engineering Contradiction:
Improvedata loss preventionVSAvoidmodel update time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs validation and verification operations in advance before model version failover. Syntax validation, semantic validation, and consistency checks are executed on the target version beforehand. This preliminary action ensures data integrity is maintained during failover while reducing the actual update time, as the safeguards are already in place rather than being applied during the critical failover moment.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If rigorous management of model failover is enforced, then data loss is minimized, but operational flexibility and adaptability to network evolutions are reduced

Engineering Contradiction:
Improvedata loss during deploymentVSAvoidnetwork evolution adaptability
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic model version management system where the relationship between current and target versions is flexible and adaptable. The system allows for dynamic switching between versions based on validation results and operational requirements. This dynamic approach maintains data integrity through controlled failover while enabling the system to adapt to network evolutions and changing requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the model management process into distinct, independently controllable stages: model definition, versioning, validation, and failover. This segmentation allows rigorous data protection measures to be applied at specific critical points while leaving other areas flexible and adaptable. Network evolutions can be accommodated by modifying individual segments without affecting the entire system's data integrity safeguards.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2746977B1Method for generating a version of a model for supervising an information system
Publication Date: 2020.02.26 CASSIDIAN CYBERSECURITY
  • EP2746977B1 patent drawingFigure 1
  • EP2746977B1 patent drawingFigure 2
  • EP2746977B1 patent drawingFigure 3

AI summary

The device has a controller generating a revision of a current version of a model starting from data of revision of previous version of the model, and conserving the total identity of the previous version of the model, where the total identity defines the total identity of current version of the model. The controller reproduces the data of components of the previous version of the model, where each component includes a local identification, and all the data of association of components of the previous version of model are reproduced. The components include physical components such as a server, a router, a set of PC, a network connection link, a geographical site, and a building.