Registration Server for Secure Test Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for configuring network nodes for testing in live and private networks are insecure and require significant manual setup, as they necessitate opening ports in firewalls and performing network address translation (NAT) mappings, which can lead to security concerns and increased support work.

Innovation Solution

A method and system that utilize a registration server to receive test configuration information, allowing communication through firewalls and NAT devices without opening ports or performing manual IP mappings, by using mechanisms like endpoint registration, inverse connections, and keep-alive messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SSH or HTTP tunneling is used to allow test configuration information to traverse firewall devices and NAT devices, then communication between test operators and network nodes is enabled, but security is compromised because ports must be opened in firewall devices and manual IP mappings are required

Engineering Contradiction:
Improvecommunication capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a registration server as an intermediary component that mediates communication between test operators and network nodes. The registration server stores node identification information and facilitates test configuration transmission without requiring direct connections through firewalls or NAT devices, thereby maintaining network security while enabling communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary registration of network nodes with the registration server before testing begins. Node identification information is stored in advance, and test operators can retrieve this information to establish secure communication channels without needing to open firewall ports or perform manual IP mappings at the time of testing.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If SSH or HTTP tunneling is implemented for each test route, then test configuration information can be transmitted, but significant product support work is required because each route needs a tunnel and manual setup of public IP endpoints is needed

Engineering Contradiction:
Improveconfiguration capabilityVSAvoidsetup complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The registration server serves multiple functions: it stores node identification information, manages test configuration data, and facilitates communication for multiple test routes simultaneously. This universal component eliminates the need to set up separate tunnels and perform manual IP mappings for each individual test route, significantly reducing setup complexity and support requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10097442B2Methods, systems, and computer readable media for receiving test configuration information
Publication Date: 2018.10.09 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US10097442B2 patent drawing
  • US10097442B2 patent drawing
  • US10097442B2 patent drawing

AI summary

Methods, systems, and computer readable media for receiving test configuration information are disclosed. According to one exemplary method, the method occurs at a node configured to operate in a private network. The method includes registering node identification information with a registration server. The method also includes sending a keep-alive message to the registration server. The method further includes receiving, in response to the keep-alive message and via the registration server, test configuration information from a configuration system outside the private network.