Rules-Based Network Agent for Secure Software Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks deployed on customer premises lack centralized management, leading to inefficient issue resolution and increased operational costs due to vendor visibility limitations, while cloud-based implementations face security concerns from sharing sensitive data.

Innovation Solution

A network management agent is deployed within the customer's network to manage software/firmware updates, evaluating vendor-provided rules without exposing sensitive customer data, using a secured connection to a vendor's cloud for centralized management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a cloud-based implementation is used to manage Wi-Fi networks, then centralized management and vendor visibility are improved, but security risks increase due to sharing sensitive customer data

Engineering Contradiction:
Improvecentralized managementVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A network management agent is deployed as an intermediary component within the customer's network to facilitate secure communication between the customer's Wi-Fi network and the vendor's cloud system. The agent acts as a mediator that enables centralized management functions while maintaining data privacy by processing information locally before sharing only necessary aggregated data with the cloud, thus resolving the contradiction between centralized management benefits and security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a dedicated server or private cloud is used for Wi-Fi network management, then data privacy is maintained, but operational efficiency decreases due to lack of centralized management

Engineering Contradiction:
Improvedata privacyVSAvoidoperational efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The network management agent serves as an intermediary that enables the customer's on-premises network to access centralized cloud management capabilities without compromising data privacy. The agent processes and aggregates data locally, sharing only necessary information with the cloud while maintaining customer data sovereignty, thus achieving both data privacy and operational efficiency benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments management functions by deploying a local agent that handles data processing and decision-making autonomously within the customer's network, while only sharing aggregated insights and control commands with the centralized cloud. This segmentation allows data to remain private while still benefiting from centralized management expertise and resources.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If no centralized management is implemented, then data security is maintained, but issue resolution efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoidissue resolution time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The network management agent acts as a secure intermediary that enables issue resolution through centralized management without compromising data security. The agent collects diagnostic information and performance metrics locally, transmits only necessary data to the cloud for analysis, and receives guidance for resolving issues, thus reducing issue resolution time while maintaining data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388736B2Rules driven software deployment agent
Publication Date: 2025.08.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12388736B2 patent drawing
  • US12388736B2 patent drawing
  • US12388736B2 patent drawing

AI summary

The disclosed embodiments provide for rules-based deployment of software installations. In some aspects, operational parameters for a computer system are monitored over time to generate a historical database of values for the operational parameters. The computer system may include multiple instances of a software installation. A portion of the multiple instances is updated with a new version of software. The operational parameters are then monitored to quantify whether the new version results in an improvement or degradation of performance of the computer system. The improvement or degradation is based on comparing values of the operational parameters after deployment to their historical values. Depending on the evaluation of the operational parameters after the installation, the installation may be rolled back if a degradation is indicated. Otherwise, the new software version may be propagated to additional installation instances.