Access Control Server Dynamic IP Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In access control systems, client devices often face difficulties in smoothly accessing resources due to dynamic IP address assignment and the inability to set communication filter information in advance, leading to interrupted communication between client and access target devices.

Innovation Solution

An access control information generation system that includes policy information storage, user information storage, access request reception, access control information transmission, address acquisition, and communication filter information generation and transmission, enabling permission-based access control and communication filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication filter device blocks communication by default, then security is improved, but client device cannot access access target resource smoothly

Engineering Contradiction:
ImprovesecurityVSAvoidaccess smoothness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access control information generation server performs preliminary actions by acquiring the client device's address information when an access request is received, generates communication filter information in advance, and transmits it to the communication filter device before the actual access occurs. This preliminary setup ensures that the communication filter device is already configured to permit the specific client device's communication, thus maintaining security while enabling smooth access without interruption.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If IP address is assigned dynamically, then network flexibility is improved, but communication filter information cannot be set in advance

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsetup time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by acquiring the client device's address information at the moment an access request is received, before the actual access proceeds. Even though IP addresses are dynamically assigned, the server quickly obtains the current address, generates communication filter information immediately, and transmits it to the communication filter device in advance of the actual data transmission. This eliminates setup delays during actual access while preserving dynamic IP assignment flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control information generation server acts as an intermediary between the client device and the communication filter device. It receives access requests from client devices, generates appropriate communication filter information based on policy information, and transmits this information to the communication filter device. This intermediary role enables the system to handle dynamic IP addresses efficiently by translating client device addresses into appropriate filter rules in real-time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If access control information is customized for each resource, then access control precision is improved, but setup complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsetup complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access control information generation server provides a universal solution that handles multiple access target resources through a single system. Instead of requiring separate manual configuration for each resource, the server universally applies policy information across all resources, automatically generating customized access control information for each client device-resource pair based on the stored policies. This multi-functional approach maintains precise access control while eliminating the complexity of individual resource setup.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service by automatically generating customized access control information for each resource based on pre-stored policy information. When an access request is received, the server autonomously retrieves relevant policy information, generates appropriate access control information for that specific resource, and transmits it without requiring manual intervention. This self-service mechanism maintains high access control precision while eliminating setup complexity for users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9363290B2Access control information generating system
Publication Date: 2016.06.07 NEC CORP
  • US9363290B2 patent drawing
  • US9363290B2 patent drawing
  • US9363290B2 patent drawing

AI summary

A system 100 stores policy information in which role identification information, resource group identification information and action information are associated with each other (101), stores user identification information and role identification information in association with each other (102), receives an access request including user identification information for identifying a user of a client device (103), generates access control information based on the policy information and transmits the generated access control information to an access target device (104), acquires address information of a transmission source of the access request (105), and generates communication filter information representing permission for communication relating to an address represented by the acquired address information and transmits the generated communication filter information to a communication filter device specified based on the policy information (106).