Authorization Data Model Translation Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems face interoperability issues due to vendor-specific authorization data models, limiting the integration of devices from different vendors and hindering the adoption of advanced network access control strategies.

Innovation Solution

The implementation of a vendor-neutral authorization data model, such as the IF-MAP standard, allows for the translation of authorization information between different vendor-specific models, enabling devices to publish and retrieve authorization data despite using proprietary models, thereby reducing the complexity of export and import policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vendor-specific authorization data models are used, then each device can maintain its own proprietary authorization model, but interoperability between devices from different vendors is limited

Engineering Contradiction:
ImproveinteroperabilityVSAvoidauthorization data model complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a translation server as an intermediary component that mediates between authorization devices using different vendor-specific data models. The server translates authorization information from one vendor's data model to another vendor's data model, enabling interoperability without requiring each device to support multiple proprietary models. This resolves the contradiction by adding a specialized intermediary layer that handles model translation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The translation server implements a universal authorization data model that can interface with multiple different vendor-specific models. Rather than requiring each authorization device to support all possible vendor models, the universal server acts as a gateway that translates between any combination of vendor models, providing multi-functionality and broad adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a single vendor provides both authentication server and firewall, then coherent network access control strategy is achieved, but enterprise flexibility and technology adoption are limited

Engineering Contradiction:
Improvecoherent network access control strategyVSAvoidenterprise flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The translation server serves as a mediator that enables coherent network access control strategies across multi-vendor deployments. By translating authorization information between different vendor models, the server ensures that authentication servers and firewalls from different vendors can work together seamlessly, maintaining strategy coherence without requiring single-vendor integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network access control function into separate components (authentication server, translation server, firewall) that can be provided by different vendors. The translation server acts as an independent intermediary layer that maintains the coherence of the overall strategy while allowing each component to be optimized by its respective vendor.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If vendor-specific authorization models are maintained, then secure proprietary authorization is preserved, but integration of devices from various vendors becomes difficult

Engineering Contradiction:
Improvedevice integrationVSAvoidauthorization information translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The translation server acts as a dedicated intermediary that handles all authorization information translation between vendor-specific models. This centralizes the translation complexity in a single component, protecting the proprietary authorization models of individual vendors while enabling their integration. Each vendor can maintain their secure proprietary model without exposing it to other vendors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The translation server creates copies of authorization information in different data model formats simultaneously. Rather than converting models directly between vendors, the server maintains copies in each vendor's proprietary format and translates between these copies, preserving the integrity of each vendor's authorization model while enabling integration.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8291468B1Translating authorization information within computer networks
Publication Date: 2012.10.16 PULSE SECURE LLC
  • US8291468B1 patent drawing
  • US8291468B1 patent drawing
  • US8291468B1 patent drawing

AI summary

In general, techniques are described for translating authorization information within computer networks. For example, a first network device of a computer network may receive authentication information from an endpoint device requesting access to the computer network. The first network device authenticates the endpoint device based on this authentication information and stores authorization information in accordance with a first vendor-specific authorization data model. The first network device stores and applies an export translation policy to translate this information from the vendor-specific data model to a vendor-neutral authorization data model, which it then publishes to an intermediate storage device that implements the vendor-neutral data model. A second network device of the computer network may store an import translation policy to translate this same authorization information from the vendor-neutral authorization data model to a different vendor-specific data model. In this manner, the techniques facilitate translation of authorization information within computer networks.