Automated Network Security Device Deployment via Centralized Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment and configuration of network security devices are time-consuming and often require skilled personnel, leading to potential configuration issues and security breaches when deploying multiple devices at different locations, especially when non-technical personnel are involved.

Innovation Solution

A system and method for rapid deployment of network security devices using network-accessible security and management modules, where an administrator specifies configuration information that is automatically pushed to the device upon deployment, transitioning it from a factory default state to a production-ready state, including preconfigured parameters and credentials for secure connection and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual deployment and configuration methods are used, then deployment accuracy and security can be ensured, but deployment time and resource requirements increase significantly

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring security devices at the factory with baseline security policies and credentials before deployment. This allows the devices to be quickly activated at customer sites without requiring extensive on-site configuration work, thus reducing deployment time while maintaining configuration accuracy through factory-tested setups.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service deployment where security devices automatically retrieve and apply configuration policies from a centralized management server upon activation. The devices self-configure their security parameters, certificates, and policies without requiring manual intervention, which dramatically reduces deployment time while ensuring consistent, accurate configuration through automated processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If skilled personnel are used for deployment, then configuration quality improves, but deployment cost and complexity increase

Engineering Contradiction:
Improveconfiguration qualityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system replaces the need for skilled personnel with self-service automation. Security devices automatically obtain configuration policies, security certificates, and operational parameters from a centralized management server through automated protocols. This eliminates the need for specialized knowledge at deployment sites while ensuring high configuration quality through centrally-managed, consistently-applied security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces a centralized management server as an intermediary between device manufacturers and deployment personnel. This server stores and distributes pre-configured security policies, credentials, and device parameters, acting as a mediator that ensures configuration quality without requiring skilled operators at each deployment site. The intermediary centralizes expertise while enabling simple local deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If standardized configuration is used, then deployment speed increases, but adaptability to specific locations decreases

Engineering Contradiction:
Improvedeployment speedVSAvoidlocation-specific adaptability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by allowing each security device to receive location-specific configuration parameters from the centralized management server. While the deployment process itself is standardized and automated, the actual security policies, network parameters, and operational settings are customized for each specific deployment location. This enables fast standardized deployment while maintaining local adaptability through server-distributed location-specific configurations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9003485B2Systems and methods for the rapid deployment of network security devices
Publication Date: 2015.04.07 WATCHGUARD
  • US9003485B2 patent drawing
  • US9003485B2 patent drawing
  • US9003485B2 patent drawing

AI summary

A configuration service comprises a deployment package and a production configuration for a network security device. One or more configuration parameters of the production configuration may be defined by an administrator of the network security device (e.g., the customer). The network security device may be preconfigured with a network address and identifier. The network security device may be configured to automatically request and apply the deployment package at deployment time by use of the preconfigured network address and identifier. The network security device may automatically request and apply the production configuration from the configuration service in response to applying the deployment package.