Server Context Segmentation for Multi-Interface Network Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-IP system management approaches fail to securely manage devices across multiple network interfaces, as they do not adequately isolate subnets connected through different interfaces, potentially compromising private networks if not properly secured.

Innovation Solution

Implementing a mechanism where each server context comprises one or more server ranges, each associated with a specific network interface and set of management policies, allowing devices to be managed from any configured interface while maintaining isolation between subnets, and enabling role-based access control to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a communication bridge is built between the primary interface and a secondary interface, then devices can be managed through multiple network interfaces, but the subnets of devices connected through different interfaces are not secured from each other

Engineering Contradiction:
Improvedevice management capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the server contexts into separate, isolated segments. Each server context is associated with specific network interfaces and device subnets, creating distinct management domains. This segmentation allows devices to be managed through multiple interfaces while maintaining security isolation between different subnets, preventing harmful cross-subnet access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces server contexts as intermediary entities between network interfaces and managed devices. Each server context acts as a mediator that manages devices through specific interfaces while maintaining isolation boundaries. This intermediary structure enables versatile device management without direct exposure between different subnet contexts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single network address and port is identified as the event destination, then the management server can simplify event processing, but the server can only manage devices connected to the primary interface unless a communication bridge is present

Engineering Contradiction:
Improveevent processing complexityVSAvoidinterface management capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the event processing mechanism by associating different server contexts with specific network interfaces and event destinations. Instead of a single event destination handling all interfaces, each server context has its own event destination tied to specific interfaces, enabling independent event processing for each interface while maintaining overall system organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to event destination identification by introducing server context association. Rather than solely using network address and port, the system now incorporates server context as an additional dimensional identifier, enabling devices to be managed through multiple interfaces while maintaining structured event processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If the management server manages all devices connected through any interface, then the server provides comprehensive device management, but the server cannot selectively manage only certain portions of devices without additional configuration

Engineering Contradiction:
Improvedevice management coverageVSAvoidserver configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments device management into separate server contexts, each associated with specific network interfaces and device subnets. This segmentation enables comprehensive management of all connected devices while allowing selective management of portions by simply choosing which server contexts to activate or configure, reducing the complexity of selective management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning specific management policies and characteristics to each server context based on its associated network interfaces and subnets. Each server context has localized management properties that can be independently configured, enabling selective management of device portions without affecting other contexts.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7418490B1System using multiple sets of device management policies for managing network devices connected on different network interfaces
Publication Date: 2008.08.26 ORACLE AMERICAN INC
  • US7418490B1 patent drawing
  • US7418490B1 patent drawing
  • US7418490B1 patent drawing

AI summary

A mechanism for managing network devices using a server with multiple network interfaces includes management agents executing on managed devices, wherein all the agents that share a single instance of a management server, or that are logically partitioned, are said to be in a single “server context”. Each server context can manage devices from any of multiple network interfaces of a server machine, that are associated with a given server context. Managed devices that are registered to be managed as part of a given server context are managed based on policies associated with the server context. Managed devices that are registered to be managed through one network interface of a server context of the management server may be communicatively isolated from managed devices that are registered to be managed through another network interface of the same server context of the management server.