Optical NMS Domain Partitioning for Multi-Client Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to managing optical communication systems in multi-party environments require dedicated Element Management Systems (EMS) and Network Management Systems (NMS) for each party, leading to inefficiencies in hardware usage, increased costs, and technical complexities due to the need for fine-grain control and data privacy across shared and party-specific equipment.

Innovation Solution

A single NMS system that logically partitions the optical communication system by domain, using a proxy server approach for authentication and secure user access, allowing each party to maintain separate authentication databases and control access to specific equipment based on fiber pair, wavelength, or hardware elements, thereby reducing the need for duplicate hardware and enhancing data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated EMS and NMS hardware and software are provided for each party, then data security and operational independence are improved, but hardware costs and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the NMS functionality by implementing domain-specific partitions within a single NMS system. Each domain (party) has its own configuration space, authentication database, and equipment view, creating logical separation without physical duplication. This allows multiple parties to operate independently with secure data isolation while sharing common infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The single NMS system is designed to serve multiple domains and parties simultaneously through universal hardware and software that can be dynamically configured. The system can authenticate users from different domains, manage different equipment sets, and enforce different access policies using the same physical infrastructure, eliminating the need for separate dedicated systems for each party.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If dedicated EMS and NMS hardware and software are provided for each party, then operational independence is improved, but hardware costs increase

Engineering Contradiction:
Improveoperational independenceVSAvoidhardware quantity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system divides the operational space into domain-specific partitions where each party has independent control over their configured equipment and parameters. This logical segmentation provides operational independence without requiring separate physical hardware systems for each party.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple domain-specific NMS instances are merged into a single shared NMS system. The system combines authentication databases, configuration management, and equipment control into one unified platform that serves all parties, reducing hardware quantity while maintaining operational independence through virtualization and domain partitioning.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If a single NMS system is used for multiple parties, then hardware costs and system complexity are reduced, but access control and data security become more difficult to manage

Engineering Contradiction:
Improvesystem complexityVSAvoidaccess control
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The single NMS system is segmented into domain-specific partitions, each with its own authentication database and access control policies. This segmentation allows independent management of access rights for each party while using a unified system, making access control as manageable as separate systems but with reduced complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces domain identifiers and authentication intermediaries that mediate between users and the NMS system. These intermediaries enable fine-grained access control by routing authentication requests through domain-specific validation layers, simplifying the management of complex multi-party access requirements within a single system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If dedicated EMS and NMS systems are provided for each party, then data privacy is improved, but maintenance costs and technician requirements increase

Engineering Contradiction:
Improvedata privacyVSAvoidmaintenance efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

Data privacy is maintained through segmented domain partitions that isolate each party's configuration data and equipment information. The system architecture ensures that each domain's data remains confidential and accessible only to authorized users of that domain, providing the same data privacy protection as dedicated systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Maintenance operations for multiple domains are merged into a single unified system, allowing technicians to service the entire NMS infrastructure through one platform. This eliminates the need to maintain separate dedicated systems for each party, reducing maintenance costs and improving efficiency while data privacy is preserved through domain isolation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11044252B2Techniques for secured partitioning of an optical transmission system to provide multi-client management access and a network management system implementing same
Publication Date: 2021.06.22 SUBCOM LLC
  • US11044252B2 patent drawing
  • US11044252B2 patent drawing
  • US11044252B2 patent drawing

AI summary

A system and method consistent with the present disclosure allows for a single NMS system to manage data access and control for N number of customer domains and associated users. In particular, an NMS consistent with the present disclosure may include a configuration that partitions the optical communication system by domain. For each domain, partitioning can further define per-user access constraints and privileges including access to specific equipment by, for instance, fiber pair designation, wavelength designation, specifically identified hardware elements, component categories, or any combination thereof. The NMS system may utilize a proxy server approach to authentication, e.g., using RADIUS, that allows for each party/customer to maintain separate authentication databases and equipment-specific constraints. The NMS may therefore validate users and enforce domain restrictions via the partitioning information such that each user has a secure ‘view’ of only those portions of the system associated with their particular domain.