Access Control List Lockout Prevention in Networking Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The application of access control lists in information handling systems can lead to network administrators being locked out of networking devices, resulting in wasted time, productivity losses, and embarrassment due to unintended configuration mistakes.

Innovation Solution

An access control list lockout prevention system that warns administrators if they will lose access to a networking device upon executing an access control list instruction, allowing them to modify the list to prevent lockouts before applying it.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an access control list is applied to a networking device to restrict unauthorized access, then security is improved, but the network administrator may lose access to the device

Engineering Contradiction:
ImprovesecurityVSAvoidadministrator access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of the access control list configuration before applying it to the networking device. It identifies administrator IHSs that would lose access and warns the network administrator in advance, allowing them to modify the configuration to preserve their access while still achieving security restrictions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to the network administrator by displaying a warning message that identifies which administrator IHSs will lose access. This feedback loop allows the administrator to review and adjust the access control list configuration before deployment, preventing lockout while maintaining security.

Inventive Principle:
Principle #23Feedback

2Productivity

If an access control list is applied without verification, then configuration speed is improved, but lockout mistakes increase

Engineering Contradiction:
Improveconfiguration speedVSAvoidconfiguration accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs automatic verification of administrator access status before the access control list is applied. This preliminary check identifies potential lockout scenarios without requiring manual verification, maintaining fast configuration deployment while preventing mistakes through automated analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The networking device automatically analyzes the access control list configuration and identifies which administrator IHSs would be affected. This self-service verification eliminates the need for manual checking by the network administrator, maintaining productivity while improving configuration accuracy through automated error prevention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9509700B2Access control list lockout prevention system
Publication Date: 2016.11.29 DELL PROD LP
  • US9509700B2 patent drawing
  • US9509700B2 patent drawing
  • US9509700B2 patent drawing

AI summary

An access control list lockout prevention system includes a network. A first administrator Information Handling System (IHS) is coupled to the network. A networking device is communicatively connected to the first administrator IHS through the network. The networking device is configured to receive an access control list instruction from the first administrator IHS. The networking device then determines that at least one administrator IHS that is communicatively connected to the networking device will lose access to the networking device in response to execution of the access control list instruction. In response to determining that the at least one administrator IHS will lose access to the networking device in response to execution of the access control list instruction, the networking device provides a warning message for display on the first administrator IHS.