Port Management System for Automated Switch Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex converged network environments, managing switch provisioning for proper network resources, quality of service, and security policies is burdensome, leading to delays that can expose the LAN to malicious attacks and service degradation.

Innovation Solution

A port management system that automatically provisions network resources based on defined network events, using profiles that contain commands for dynamic port configuration changes, which can be created, edited, and stored via a command line interface or network management system, and executed upon events such as user authentication or device detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proprietary centralized network management system is used to provision switch ports with network resources and policies, then the switch can be properly configured with correct network resources, quality of service, and security policy, but there is a delay between device authentication and policy deployment that exposes the LAN to malicious attacks

Engineering Contradiction:
ImprovesecurityVSAvoiddelay in policy deployment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring profile data on the switch itself before authentication events occur. The switch stores multiple profiles containing configuration parameters, command line interface commands, and script data that can be immediately executed when authentication events are detected, eliminating the delay of waiting for centralized system responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of locally stored profile data that acts as a bridge between authentication events and policy deployment. Instead of direct communication between the centralized network management system and the switch during authentication, the pre-stored profiles serve as an intermediary that enables immediate local policy application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If manual configuration of switch ports is performed to ensure proper provisioning with network resources and policies, then configuration accuracy can be maintained, but the process becomes burdensome and time-consuming

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidease of provisioning
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent applies self-service by enabling the switch to automatically provision itself with configuration data and policies based on authentication events. The switch executes stored profiles locally without requiring manual intervention from network administrators, making the system self-configuring while maintaining accuracy through pre-defined profile data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses preliminary action by pre-defining configuration profiles with accurate network resources, quality of service, and security policy parameters before deployment. These pre-configured profiles ensure configuration accuracy while eliminating the need for manual provisioning operations.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If centralized network management systems are used to deploy policies, then comprehensive network control can be maintained, but the complexity of managing deployment increases

Engineering Contradiction:
Improvenetwork controlVSAvoidcomplexity of policy deployment management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the policy deployment function into two parts: centralized profile data creation and local profile execution. The complex task of policy management is segmented between the network management system (which creates and updates profiles) and the individual switches (which execute profiles locally), reducing the overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces profile data as an intermediary layer between the centralized network management system and individual switches. This intermediary structure simplifies management by providing a standardized interface for policy deployment while maintaining comprehensive network control through centralized profile definition.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8751649B2Port management system
Publication Date: 2014.06.10 EXTREME NETWORKS INC
  • US8751649B2 patent drawing
  • US8751649B2 patent drawing
  • US8751649B2 patent drawing

AI summary

A method is provided for a port management system in which a switch is automatically provisioned with network resources. A command or set of commands are stored and automatically executed on the switch upon the occurrence of a defined network event. The command or set of commands may be associated with one or more ports on the switch. When executed, the commands cause a change to a port configuration and/or policy on the switch to control access to a network resource. The network resource may include any device or service accessible on the network. The defined network event may include any network event associated with a device or user connected to the network. The command or set of commands may reference variables, control structures, and functions to modify command execution.