Access Control via Verification Codes to Reduce ACL Complexity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control mechanisms in enterprise campus networks, relying on access control lists (ACLs), are complex and costly to maintain, requiring real-time management and updates, which increases operational overhead and compromises network security.
Innovation Solution
An access control method that reduces the reliance on ACLs by using a verification process based on association attributes and target information, where a computer device sends a source and target identifier to a network device, receives a verification code, and sends a packet including this information to access a target resource, ensuring packet verification and improving network security in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented using traditional ACL mechanisms, then network security can be ensured, but the system complexity and manual maintenance costs increase significantly
Solution Approach 1:
The patent extracts the access control verification function from the traditional ACL mechanism and relocates it to the application layer. Instead of relying on network layer ACLs that require complex manual maintenance, the system uses application-level verification codes generated by a verification server. This extraction simplifies the network infrastructure while maintaining security through application-layer validation.
Solution Approach 2:
The patent introduces a verification server as an intermediary component between the terminal device and the target resource. This intermediary generates verification codes based on association attributes and target constraint items, then validates packets before allowing access. The verification server centralizes the access control logic, eliminating the need for complex distributed ACL management across multiple network devices.
2Reliability
If traditional ACL access control is used, then unauthorized access can be prevented, but real-time management and updates require high manual operation costs
Solution Approach 1:
The verification server automatically generates verification codes based on association attributes and target constraint items without requiring manual ACL configuration or updates. The system self-manages access control by dynamically creating verification codes that incorporate real-time information such as user attributes, target resource characteristics, and constraint conditions. This eliminates manual maintenance operations while maintaining effective access control.
Solution Approach 2:
The patent changes the parameters of access control from static ACL entries to dynamic verification codes. Instead of using fixed network layer rules that require manual updates, the system generates verification codes that incorporate variable association attributes and target constraint items. These parameters can be dynamically adjusted based on real-time conditions, eliminating the need for manual ACL reconfiguration while maintaining security.
3Ease of manufacture
If ACL entries are maintained manually, then access control can be implemented, but the overhead and operational burden increase
Solution Approach 1:
The verification server performs preliminary actions by pre-establishing association attributes and target constraint items before actual access occurs. The system pre-generates verification codes that incorporate all necessary access control logic, eliminating the need for manual ACL entry maintenance during operation. This preliminary preparation of verification parameters significantly reduces maintenance time and operational burden.
Data Source
AI summary
An access control method includes: A computer device sends a source identifier and a target identifier to a first network device; and the first network device determines, based on the source identifier, the target identifier, and an access control list, an association attribute and a first target constraint item corresponding to the association attribute, determines a first verification code based on the association attribute and the first target constraint item corresponding to the association attribute, and then sends, to the computer device, first indication information that includes at least the first verification code. Then, the computer device determines the association attribute and first target information corresponding to the association attribute, adds, to a packet for accessing a target resource, the association attribute and the first target information corresponding to the association attribute, and sends the packet, where the packet further includes at least the first indication information.


