Custom Role Creation for Granular Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network access control systems lack the ability to customize user roles and privileges effectively, limiting service providers' control over user access and service offerings in multi-tenant environments.

Innovation Solution

The system allows service providers to create custom roles with specific sets of actions and privileges, enabling granular control over user access by associating users with these custom roles, which can be modified based on user input, thereby extending the control provided by pre-defined roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pre-defined roles from open-source software are used, then system reliability is maintained, but adaptability to customize user access control is insufficient

Engineering Contradiction:
Improvecustomization of user roles and privilegesVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments role management into two distinct components: pre-defined roles from open-source software that ensure system reliability, and custom roles that can be created and configured by service providers to meet specific customization needs. This segmentation allows both reliability and adaptability to coexist by isolating the stability-providing elements from the flexibility-providing elements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges pre-defined roles and custom roles into a unified role management framework where both types of roles can be assigned to users simultaneously. This combination allows the system to leverage the stability of pre-defined roles while incorporating the flexibility of custom roles, resolving the contradiction between reliability and adaptability.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If custom roles are created with specific capabilities, then adaptability of access control is improved, but device complexity increases

Engineering Contradiction:
Improvecustomization of user roles and privilegesVSAvoidrole management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by providing pre-defined roles with common capability sets before custom role creation is needed. Service providers can start with these pre-configured roles and only create custom roles when specific customization requirements arise, reducing the overall complexity while maintaining necessary adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The role management system is designed to be dynamic, allowing service providers to create, modify, or delete custom roles based on changing requirements. This dynamic approach means that complexity only increases when and where it is needed, rather than being statically present throughout the entire system.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If granular control over user actions is implemented, then adaptability of service offerings is improved, but ease of operation decreases

Engineering Contradiction:
Improvecontrol over user actions and service accessVSAvoiduser interface complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements a universal capability framework where capabilities are standardized and can be applied across multiple roles and users. This multi-functionality allows granular control to be achieved through a consistent interface, reducing operational complexity while maintaining fine-grained control over user actions and service access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12184659B2Creating roles and controlling access within a computer network
Publication Date: 2024.12.31 JUNIPER NETWORKS INC
  • US12184659B2 patent drawing
  • US12184659B2 patent drawing
  • US12184659B2 patent drawing

AI summary

This disclosure is directed to devices, systems, and techniques for enforcing access to resources within a computer network. In some examples, a system includes a network managed by a service provider and configured to provide a plurality of microservices to a plurality of tenants each having one or more users and a controller having access to the network. The controller is configured to output, to a user interface, data indicative of a plurality of capabilities for presentation by the user interface and receive, from the user interface, data indicative of a user selection of a set of capabilities and a user selection of a new role identifier. The controller is further configured to create, based on the set of capabilities and the role identifier, a role which enables access to a set of actions within a computer network, the set of actions corresponding to the set of capabilities.