Network Management System for Dial-Out Session Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant SaaS environments, establishing dial-out communication sessions does not allow for unique identification of devices and tenants, leading to inadequate resource allocation and performance issues due to overloaded connectivity service instances.
Innovation Solution
A network management system (NMS) generates and manages certificates with identification information for endpoint devices, ensuring proper authentication and load balancing across multiple connectivity service instances to facilitate efficient resource allocation and service provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If dial-out communication sessions are established without certificate-based identification, then device and tenant identification is lost, but system complexity increases when implementing certificate management
Solution Approach 1:
The system performs preliminary actions by generating and distributing certificates to endpoint devices before they initiate dial-out communication sessions. The certificate orchestrator pre-configures identification information in certificates, so that when devices connect, their identity is already established, eliminating the need for complex runtime identification procedures.
Solution Approach 2:
The patent introduces a certificate orchestrator as an intermediary component that manages certificate generation, distribution, and validation. This mediator handles the complexity of identification management centrally, allowing the dial-out session establishment process to remain simple while maintaining robust device and tenant identification through certificate-based authentication.
2Adaptability or versatility
If connectivity service instances handle all dial-out sessions, then service coverage is comprehensive, but performance degrades due to overloading
Solution Approach 1:
The system segments the connectivity service into multiple independent instances, each capable of handling dial-out sessions. The load balancer distributes sessions across these segmented instances based on their current workload and capacity, preventing any single instance from becoming overloaded while maintaining comprehensive service coverage through the collective capacity of all instances.
Solution Approach 2:
The patent implements dynamic load balancing where the load balancer continuously monitors the state of connectivity service instances and dynamically adjusts session distribution in real-time. Instances can be added or removed from the active pool based on demand, allowing the system to adapt to varying workload conditions while maintaining optimal performance across all instances.
3Productivity
If load balancing is implemented across connectivity service instances, then resource allocation improves, but system complexity increases
Solution Approach 1:
The load balancer operates autonomously, automatically monitoring the health and workload of connectivity service instances and making real-time decisions about session distribution without requiring manual intervention. The system self-adjusts to changing conditions, adding or removing instances from the load-balanced pool based on their operational state, thereby improving resource allocation while minimizing the operational complexity burden on users.
Data Source
AI summary
A system determines identification information associated with an endpoint device, which is associated with a tenant of the system, and the tenant. The system generates and sends, to the endpoint device, a certificate that includes the identification information. The system receives, from the endpoint device and as part of an attempt by the endpoint device to initiate a dial-out communication session with the system, the certificate. The system causes, based on the certificate, the dial-out communication session to be established and processes the certificate to determine the identification information. The system receives, from the endpoint device and via the dial-out communication session, one or more messages; modifies the one or more messages to include the identification information; and provides the one or more modified messages to facilitate provisioning of services or resources associated with the system to the endpoint device.


