Dynamic Access Control Entry Generation for IP Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for data centers face challenges in dynamically managing access control policies, especially in handling changes in IP addresses of access accounts while ensuring secure and flexible access permissions.

Innovation Solution

A method and apparatus for processing access requests that involve acquiring identification information and IP addresses from authentication messages, determining matching permission configuration information, generating access control entries, and processing access requests based on these entries, allowing for dynamic management of access control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems are used with static IP address binding, then security management is simplified, but the system cannot adapt to dynamic IP changes and loses flexibility

Engineering Contradiction:
ImproveAdaptability to IP address changesVSAvoidAccess control policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by automatically generating and updating access control entries when IP addresses change. The system transitions from static IP binding to dynamic IP adaptation, where the access control policy is automatically adjusted based on authentication messages containing new IP addresses, eliminating the need for manual policy updates while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The access control system performs self-service by automatically detecting IP address changes from authentication messages and generating updated access control entries without requiring manual intervention. The system self-manages the policy updates, reducing administrative complexity while improving adaptability to dynamic networking conditions.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual access control policy updates are performed for each IP address change, then policy accuracy is maintained, but time consumption and operational overhead increase

Engineering Contradiction:
ImproveAccess control policy update efficiencyVSAvoidTime for policy management operations
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring access control templates and permission profiles that can be quickly instantiated. When IP addresses change, the system automatically applies these pre-defined templates to generate access control entries, eliminating the need for manual policy creation and significantly reducing update time while maintaining policy accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control system automatically updates policies in response to IP address changes without requiring manual intervention. The system extracts IP addresses from authentication messages and self-generates corresponding access control entries, dramatically improving productivity and eliminating time loss associated with manual policy management.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If detailed access permission management is implemented, then security control precision is improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
ImproveAccess permission control precisionVSAvoidPermission configuration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into modular permission profiles and templates that can be independently configured and reused. Each permission profile represents a discrete set of access rights that can be assigned to different users and IP addresses, enabling detailed control precision while reducing overall system complexity through modular design and template-based configuration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250119427A1Method for processing access request, apparatus, and storage medium
Publication Date: 2025.04.10 BEIJING BAIDU NETCOM SCI & TECH CO LTD
  • US20250119427A1 patent drawing
  • US20250119427A1 patent drawing
  • US20250119427A1 patent drawing

AI summary

A method and apparatus for processing an access request, and a computer readable storage medium are provided. The method includes acquiring identification information and an IP address of an access account from an authentication message; determining permission configuration information matching the identification information; generating an access control entry based on the permission configuration information and the IP address; and processing an access request of an access account based on an access control entry.