Adaptive Allow Lists for Centralized Network Resource Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing administrative approaches for managing access control lists (ACLs) in Information Handling Systems (IHSs) are cumbersome and impractical for controlling access to external resources, especially websites, leading to inefficient and insecure configurations.
Innovation Solution
Implementing adaptive allow lists that are factory-provisioned and stored on IHSs, allowing customers to specify and modify allowed network resources, with mechanisms to manage and update these lists dynamically, ensuring secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional ACLs or allow/deny lists are used to control network access, then access control functionality is provided, but administrative complexity and difficulty of management increase significantly for large numbers of users
Solution Approach 1:
The patent introduces a network server as an intermediary that hosts and manages the allow list, eliminating the need for administrators to manually configure each IHS. The server acts as a centralized repository that automatically provides access control rules to multiple IHS devices, significantly reducing administrative complexity while maintaining reliable network access control.
Solution Approach 2:
The allow list stored on the network server serves multiple IHS devices simultaneously, providing a universal access control mechanism. A single allow list configuration can be applied to numerous users and devices, eliminating the need for individualized configurations and reducing the overall complexity of managing large numbers of users.
2Reliability
If traditional allow/deny lists are used, then network resource access is controlled, but the lists become outdated and insufficiently modified over time
Solution Approach 1:
The system implements automatic feedback mechanisms where the network server continuously monitors and updates the allow list based on changing network conditions and requirements. This ensures that access control rules remain current and effective without requiring manual intervention, maintaining reliability while improving ease of operation.
Solution Approach 2:
The IHS devices automatically retrieve and apply updates to the allow list from the network server without requiring administrator intervention. This self-service mechanism ensures that access control configurations are continuously maintained and updated, preventing lists from becoming outdated while reducing operational burden.
3Reliability
If restrictive permission systems are configured for each individual IHS, then security is improved, but the complexity of configuration and administration increases
Solution Approach 1:
The network server acts as an intermediary that centralizes the management of security rules. Instead of configuring each IHS individually, administrators manage security policies on the server, which then automatically distributes and enforces these rules across all connected IHS devices. This maintains strong security controls while dramatically reducing configuration complexity.
Solution Approach 2:
The system segments the security management function into two parts: policy definition (centralized on the server) and policy enforcement (distributed to each IHS). This segmentation allows security rules to be created and modified centrally without requiring changes to each individual device, maintaining security while reducing administrative complexity.
4Reliability
If allow lists are frequently updated to maintain security, then access control effectiveness is improved, but the time and effort required for administration increases
Solution Approach 1:
The network server implements automated feedback loops that monitor network traffic and security requirements, automatically updating the allow list when changes are detected. This eliminates the need for manual updates while maintaining effective access control, reducing administration time while preserving security effectiveness.
Solution Approach 2:
IHS devices automatically retrieve updated allow lists from the network server without requiring administrator intervention. This self-service update mechanism ensures that access control effectiveness is maintained through frequent updates while minimizing the time and effort required for administration, as updates occur automatically in the background.
Data Source
AI summary
Systems and methods provide Information Handling Systems (IHSs) that are restricted to communications with a plurality of allowed network resources. An IHS detects a request for access to a network resource. Upon detecting the request, the IHS identifies a factory-provisioned network address that is stored by the IHS and that specifies a location of an adaptive allow list that specifies a listing of the allowed network resources to which the IHS is restricted. The adaptive allow list is loaded from the factory-provisioned network address and used to reject the request for access to the network resource when the network resource is not in the listing of allowed network resources from the adaptive allow list. Through modifications to the adaptive allow lists, administrators can modify the network resource that may be accessed by the IHS.


