Alarm Access Controller for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SSL VPN gateways face difficulties in handling alarms from multi-vendor products within an enterprise network, as they are not configured to deliver alarms to external service providers outside the firewall, and authenticating large numbers of service provider technicians is impractical and burdensome on the AAA server.

Innovation Solution

An alarm access controller is introduced, which processes alarms to determine severity, grants temporary authenticated access to service providers, and manages access times based on alarm severity, using an alarm severity analyzer, notice generator, trouble ticket generator, authenticator, and service-related storage to facilitate efficient access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional SSL VPN gateways are used to control access to internal resources, then basic security is maintained, but the system cannot deliver alarms to external service providers and requires manual customer authorization for each access request

Engineering Contradiction:
Improveautomatic alarm delivery and access grantingVSAvoidgateway configuration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway is segmented into specialized modules: alarm manager for receiving and routing alarms, AAA server for authentication, and access controller for granting temporary access. This segmentation allows each component to handle specific tasks efficiently, enabling automatic alarm delivery without requiring complex overall gateway configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The alarm manager acts as an intermediary between internal alarm-generating devices and external service providers. It receives alarms from internal resources, determines appropriate service providers, and automatically grants temporary access without requiring manual customer authorization for each access request.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service provider technicians are authenticated individually through the AAA server, then access security is maintained, but the authentication burden becomes excessive when hundreds or thousands of technicians need access

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements federated identity authentication that allows a single authentication mechanism to serve multiple service providers and their numerous technicians. The AAA server authenticates service providers once, and this authentication is universally accepted across multiple alarm-generating devices and service provider requests, eliminating the need for individual authentication of each technician.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary authentication of service providers before alarm delivery. Once authenticated, the service provider gains temporary access rights that are automatically validated for subsequent alarm-related access requests, eliminating repeated authentication overhead for hundreds or thousands of technicians.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If service providers are granted continuous access to internal resources, then alarm resolution is facilitated, but system security is compromised

Engineering Contradiction:
Improveservice provider accessVSAvoidsecurity risk from continuous access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic access control where service provider access rights are automatically created, activated, and deactivated based on real-time alarm conditions. Access is granted only when an alarm is present and is automatically revoked when the alarm is resolved or the time period expires, ensuring security while facilitating necessary service provider access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Service provider access is granted for specific time periods tied to alarm resolution requirements. The system periodically monitors alarm status and automatically revokes access when the specified time period elapses or when the alarm is resolved, preventing continuous unauthorized access while allowing sufficient time for alarm resolution.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8775602B2Alarm-driven access control in an enterprise network
Publication Date: 2014.07.08 AVAYA INC
  • US8775602B2 patent drawing
  • US8775602B2 patent drawing
  • US8775602B2 patent drawing

AI summary

An alarm access controller is operative to control access to an enterprise network of a communication system responsive to alarms generated by products that are part of a set of internal resources of the enterprise network. In one aspect, the alarm access controller is implemented by a server or other processing element comprising a processor coupled to a memory. The alarm access controller is configured to receive an alarm from one of the products, to identify an external service provider for handling the alarm, and to provide temporary authenticated access of the service provider to the product. By limiting service provider access to an alarm-generating product in accordance with specified time periods or other conditions determined based at least in part on the alarm itself, system security is considerably improved and access control is made more flexible and efficient.