Cloud Access Manager for IP Filtering and Domain Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing IP address-based access in geographically distributed computing services are error-prone and difficult to maintain, particularly in complex landscapes with multiple services and applications, leading to potential legal and liability issues due to incorrect access configurations.

Innovation Solution

A system that utilizes a cloud-based access manager to dynamically manage blocked IP addresses and target domains, allowing exceptions and integrating with lifecycle management, which includes a request inspector to deny or forward requests based on IP address and domain lists, and generates logs for monitoring and updating these lists periodically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of IP address lists and target domains is used, then flexibility in configuration is maintained, but error rate increases and reliability decreases

Engineering Contradiction:
Improveaccess control accuracyVSAvoidconfiguration management difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically retrieves updated IP address ranges from regional internet registries and maintains target domain lists without manual intervention. The access manager self-updates blocked IP addresses and exception domains, eliminating manual configuration errors while maintaining operational flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors and updates IP address lists by comparing current configurations against authoritative sources. Automatic feedback loops detect and correct configuration drift, ensuring high reliability without requiring manual verification or adjustment of access control lists.

Inventive Principle:
Principle #23Feedback

2Productivity

If automatic updates of IP address lists are implemented, then maintenance effort is reduced, but system complexity increases

Engineering Contradiction:
Improveconfiguration update efficiencyVSAvoidaccess management system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The access manager acts as an intermediary between external IP address registry sources and internal access control decisions. It automatically fetches, parses, and applies updates from regional internet registries, shielding the core system from complexity while maintaining high update efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-fetches and validates IP address range data from authoritative sources before it is needed for access decisions. By maintaining updated lists in advance, the system reduces real-time processing complexity while improving configuration update efficiency.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If comprehensive exception lists are maintained, then access flexibility is improved, but management difficulty increases

Engineering Contradiction:
Improveexception handling capabilityVSAvoidlist management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access manager handles multiple functions including blocked IP address filtering, target domain validation, exception list management, and automatic updates through a single unified system. This consolidates what would otherwise require multiple separate management processes into one versatile component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the management of blocked IP addresses, target domains, and exception lists into a single integrated access control mechanism. By combining these separate lists under unified automatic management, the system improves adaptability without proportionally increasing management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12074875B2Domain-specific access management using IP filtering
Publication Date: 2024.08.27 SAP SE
  • US12074875B2 patent drawing
  • US12074875B2 patent drawing
  • US12074875B2 patent drawing

AI summary

Systems and methods include reception of a request for access to a target domain, the request including a source Internet Protocol (IP) address, determination of whether the source IP address is one of a plurality of IP addresses indicated within stored first data, determination, if it is determined that the source IP address is one of the plurality of stored IP addresses, of whether the target domain is one of a plurality of domains indicated within stored second data, and forwarding, if it is determined that the source IP address is one of the plurality of stored IP addresses and the target domain is one of a plurality of domains indicated within stored second data, of the request to the target domain.