Network Management System for Dial-Out Session Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant SaaS environments, establishing dial-out communication sessions does not allow for unique identification of devices and tenants, leading to inadequate resource allocation and performance issues due to overloaded connectivity service instances.

Innovation Solution

A network management system (NMS) generates and manages certificates with identification information for endpoint devices, ensuring proper authentication and load balancing across multiple connectivity service instances to facilitate efficient resource allocation and service provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If dial-out communication sessions are established without certificate-based identification, then device and tenant identification is lost, but system complexity increases when implementing certificate management

Engineering Contradiction:
Improvedevice and tenant identificationVSAvoidcertificate management system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating and distributing certificates to endpoint devices before they initiate dial-out communication sessions. The certificate orchestrator pre-configures identification information in certificates, so that when devices connect, their identity is already established, eliminating the need for complex runtime identification procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate orchestrator as an intermediary component that manages certificate generation, distribution, and validation. This mediator handles the complexity of identification management centrally, allowing the dial-out session establishment process to remain simple while maintaining robust device and tenant identification through certificate-based authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If connectivity service instances handle all dial-out sessions, then service coverage is comprehensive, but performance degrades due to overloading

Engineering Contradiction:
Improveservice coverageVSAvoidsession processing performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments the connectivity service into multiple independent instances, each capable of handling dial-out sessions. The load balancer distributes sessions across these segmented instances based on their current workload and capacity, preventing any single instance from becoming overloaded while maintaining comprehensive service coverage through the collective capacity of all instances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic load balancing where the load balancer continuously monitors the state of connectivity service instances and dynamically adjusts session distribution in real-time. Instances can be added or removed from the active pool based on demand, allowing the system to adapt to varying workload conditions while maintaining optimal performance across all instances.

Inventive Principle:
Principle #15Dynamics

3Productivity

If load balancing is implemented across connectivity service instances, then resource allocation improves, but system complexity increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidload balancing mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The load balancer operates autonomously, automatically monitoring the health and workload of connectivity service instances and making real-time decisions about session distribution without requiring manual intervention. The system self-adjusts to changing conditions, adding or removing instances from the load-balanced pool based on their operational state, thereby improving resource allocation while minimizing the operational complexity burden on users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12166749B2Network management system for dial-out communication sessions
Publication Date: 2024.12.10 JUNIPER NETWORKS INC
  • US12166749B2 patent drawing
  • US12166749B2 patent drawing
  • US12166749B2 patent drawing

AI summary

A system determines identification information associated with an endpoint device, which is associated with a tenant of the system, and the tenant. The system generates and sends, to the endpoint device, a certificate that includes the identification information. The system receives, from the endpoint device and as part of an attempt by the endpoint device to initiate a dial-out communication session with the system, the certificate. The system causes, based on the certificate, the dial-out communication session to be established and processes the certificate to determine the identification information. The system receives, from the endpoint device and via the dial-out communication session, one or more messages; modifies the one or more messages to include the identification information; and provides the one or more modified messages to facilitate provisioning of services or resources associated with the system to the endpoint device.