Conferencing Access Logic for IP Network Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current conferencing systems fail to effectively manage access control and privilege definitions for users in telecommunications conferences, particularly in IP multimedia subsystems, leading to inadequate user authorization and conflict resolution in access lists.
Innovation Solution
Implementing a conferencing access logic using XML-based scripting that establishes allow lists, default policies, and user rights, with a uniform resource identifier for editing and management, allowing for dynamic and consistent access control across conferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional Access Control Lists (ACL) are used for conference access management, then basic user authorization can be implemented, but the system cannot handle complex privilege hierarchies, wildcard definitions, and conflict resolution between multiple access rules
Solution Approach 1:
The patent segments access control into separate policy rules that can be independently defined, evaluated, and managed. Each rule represents a discrete unit of access logic that can be combined through evaluation sequences, allowing complex access control requirements to be broken down into manageable segments rather than requiring monolithic ACL structures.
Solution Approach 2:
The patent implements dynamic policy evaluation where access decisions are made by sequentially evaluating multiple rules rather than relying on static ACL entries. The system dynamically determines access by processing rules in order, allowing the first matching rule to grant or deny access, which enables flexible handling of complex scenarios including wildcards, privilege hierarchies, and conflict resolution.
2Ease of operation
If multiple users are granted different privileges in a conference, then fine-grained access control is achieved, but managing and resolving conflicts between multiple privilege definitions becomes difficult
Solution Approach 1:
The patent applies preliminary action by establishing a defined sequence for evaluating access rules before any access decision is made. The system pre-configures the evaluation order and conflict resolution logic, so that when multiple privilege definitions exist, the system automatically processes them in the predetermined sequence, resolving conflicts before they manifest as access issues.
Solution Approach 2:
The patent introduces an intermediary policy evaluation mechanism that mediates between conflicting privilege definitions. Rather than allowing direct conflict between user privileges, the system uses an intermediate evaluation layer that processes rules sequentially and determines the effective access decision, acting as a mediator between competing access requests.
3Productivity
If wildcard patterns are allowed in ACL for bulk user management, then adding and deleting users becomes more efficient, but conflict resolution between wildcard and specific user entries becomes ambiguous
Solution Approach 1:
The patent applies local quality by allowing different rule types (wildcards and specific user entries) to coexist with distinct evaluation characteristics. Each rule maintains its local properties - wildcards provide broad matching capability while specific entries provide precise matching - and the evaluation process respects these local qualities by processing rules in a defined sequence that preserves the intended specificity of each rule type.
Data Source
AI summary
A method, apparatus, and system are disclosed for creating a conferencing access logic. The logic is for allowing access to a conference in an internet protocol (IP) network. The invention entails establishing an allow list of allowed users, setting up a default policy applicable to unlisted users, matching listed users with corresponding conference rights, and assigning a uniform resource identifier (URI) to the access logic. The URI is for identifying and editing elements of the access logic, including the allow list, the default policy, and the conference rights.


