Network Zone Scanning for Asset Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in accurately identifying and tracking computer assets across multiple subnets and geographically dispersed locations due to outdated and incomplete configuration management databases, especially when dealing with thousands of assets, which complicates digital transformation efforts.

Innovation Solution

A method utilizing scanning services connected to multiple network zones within an enterprise network to identify and validate IP addresses, collect information, and infer additional details without requiring software agents on devices, thereby allowing for analytics on the IT landscape without needing credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If agents are run on each device to collect asset information, then measurement precision of asset data is improved, but device complexity and ease of operation deteriorate due to credential management requirements

Engineering Contradiction:
Improveasset information accuracyVSAvoidcredential management complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces scanning services as intermediary components deployed in network zones that mediate between the asset discovery system and individual devices. These scanning services collect asset information without requiring direct agent installation on each device, thereby eliminating credential management complexity while maintaining measurement precision through centralized scanning operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the credential management requirement from the asset discovery process by removing agents from individual devices. Instead, asset information is collected externally through scanning services that operate at the network zone level, separating the data collection function from the target devices and eliminating the need for device-specific credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If agents are installed on each device for asset discovery, then reliability of asset data collection is improved, but device complexity increases

Engineering Contradiction:
Improveasset data collection reliabilityVSAvoidsoftware agent deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Scanning services act as intermediary components deployed in network zones that collect asset information without requiring agent installation on individual devices. This intermediary approach maintains reliable data collection through centralized scanning while eliminating the complexity of distributing and managing software agents across thousands of devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the asset discovery function from the target devices by deploying scanning services at the network zone level rather than installing agents on each device. This segmentation separates the data collection responsibility from individual devices, reducing device complexity while maintaining collection reliability through the segmented scanning service architecture.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If comprehensive scanning across multiple network zones is performed, then quantity of asset information discovered is improved, but ease of operation worsens due to firewall access requirements

Engineering Contradiction:
Improveasset information volumeVSAvoidfirewall configuration complexity
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The scanning services are designed with multi-functionality to handle diverse asset discovery tasks across different network zones through a unified interface. This universal approach allows comprehensive asset information collection across multiple zones while simplifying operations, as the same scanning service infrastructure handles all zones without requiring separate credential or firewall configurations for each zone.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If credentials are required to access computer asset information, then measurement precision of asset details is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveasset detail accuracyVSAvoidcredential management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts credential management from the asset discovery process by removing the requirement for device-specific credentials. Scanning services collect detailed asset information through network-based scanning without needing to authenticate with individual devices, thereby maintaining measurement precision while eliminating the complexity of managing credentials across numerous devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11777907B2Computer asset discovery for digital transformation
Publication Date: 2023.10.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11777907B2 patent drawing
  • US11777907B2 patent drawing
  • US11777907B2 patent drawing

AI summary

Computer assets within a defined network are identified using scanning services respectively connected to each of a plurality of network zones within the defined network. A plurality of interne protocol (IP) addresses within the particular one of the network zones are identified by a particular scanning service contained within the particular one of the network zones. The particular scanning service collects information associated with each of the plurality of IP addresses and infers, using the collected information, additional information about the plurality of IP addresses. The particular scanning service validates the additional information and presents analytics based upon the collected information and the additional information. Firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service.