Aggregation Switch ACL Rule Centralization for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control methods in enterprise networks are inefficient in managing user access authorities across multiple sub-networks and resource groups, leading to complexities in configuring and enforcing access control policies, especially when users move between different network segments.

Innovation Solution

The implementation of Software-Defined Networking (SDN) controller that configures user groups, resource groups, and access control policies, using overlay technology to establish VLAN and VXLAN identifiers, and applies ACL rules on aggregation switches to manage network access, ensuring that users access only authorized network segments and resources, regardless of their location within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ACL rules are configured on access switches to control network access, then network security is improved, but device complexity and configuration workload increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the ACL rule configuration and management functions from individual access switches and centralizes them on aggregation switches. This allows access switches to focus on basic forwarding while aggregation switches handle the complex access control policy management, reducing overall network complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal ACL rule template mechanism where a single ACL rule template can be applied to multiple user groups and network segments simultaneously. This multi-functionality reduces the number of individual ACL rules needed and simplifies configuration management across the enterprise network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If ACL rules are updated frequently to accommodate user movements, then network access control accuracy is improved, but configuration time and operational efficiency deteriorate

Engineering Contradiction:
Improveaccess control accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent pre-configures ACL rule templates on aggregation switches that define access control policies for different user groups and network segments. These templates are prepared in advance and can be quickly applied or modified without requiring frequent individual rule updates, reducing configuration time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic user group management where user memberships and ACL rule associations can be automatically updated based on user movements and role changes. This dynamic approach maintains accurate access control without requiring manual intervention for each user movement, reducing operational time.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple VLANs and ACL rules are configured to manage different user groups, then network security and access control are improved, but the number of configuration elements and system complexity increase

Engineering Contradiction:
Improveaccess controlVSAvoidnumber of configuration elements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple ACL rules into unified ACL rule templates that can cover multiple user groups and network segments. By combining related access control policies into single templates, the number of individual configuration elements is reduced while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal ACL rule templates that can be applied across multiple VLANs and user groups simultaneously. This multi-functionality reduces the total number of ACL rules needed compared to configuring separate rules for each user group and VLAN combination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11025631B2Network access control
Publication Date: 2021.06.01 NEW H3C TECH CO LTD
  • US11025631B2 patent drawing
  • US11025631B2 patent drawing
  • US11025631B2 patent drawing

AI summary

This disclosure provides a method and device for controlling network access. According to the method, an aggregation switch may configure thereon an ACL rule comprising a first network segment and a second network segment, wherein the first network segment and the second network segment correspond to a same user group or different user groups, or the first network segment corresponds to a user group and the second network segment corresponds to a resource group. The aggregation switch may, after receiving a user packet from an access switch, match a source IP address of the user packet with the first network segment, and a destination IP address of the user packet with the second network segment. If the source IP address of the user packet matches with the first network segment and the destination IP address of the user packet matches with the second network segment, the user packet is discarded.