Dynamic Access Control List Cloning for Real-Time Network Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manually generating and modifying access control lists for switches or routers is labor-intensive and time-consuming, typically performed offline, which hinders efficient network operations.
Innovation Solution
A computer system dynamically generates a clone access control list by applying editing instructions to an existing access control list or template, allowing real-time modifications while the network device is operating, using metadata tuples or configuration files to specify changes such as filter additions, deletions, or criterion changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual modification of access control lists is performed, then filtering accuracy can be maintained, but time consumption and labor intensity increase significantly
Solution Approach 1:
The patent applies the copying principle by automatically generating access control list entries through templates and patterns. Instead of manually creating each filter rule, the system copies and adapts predefined templates to generate multiple filter entries automatically, maintaining filtering accuracy while dramatically reducing time consumption and labor intensity.
Solution Approach 2:
The patent implements preliminary action by pre-defining access control list templates with common filtering patterns. These templates are prepared in advance and can be quickly instantiated and modified when needed, eliminating the need for manual creation of each filter rule from scratch while preserving filtering precision.
2Stability of the object's composition
If access control lists are generated offline, then system stability is maintained, but operational efficiency decreases
Solution Approach 1:
The patent applies the dynamics principle by enabling access control lists to be generated and modified dynamically during runtime. The system can automatically create, modify, and update filter rules based on incoming requests and predefined templates without requiring system restart or offline processing, thus maintaining stability while significantly improving operational efficiency.
3Reliability
If complex filtering criteria are implemented, then network security is enhanced, but configuration complexity increases
Solution Approach 1:
The patent applies segmentation by breaking down complex filtering criteria into modular templates and patterns. Each template represents a specific filtering scenario that can be independently configured and combined. This modular approach maintains comprehensive security coverage while reducing configuration complexity through reusable building blocks.
Solution Approach 2:
The patent implements universality through multi-functional templates that can serve multiple filtering purposes. A single template can be adapted to generate various filter rules for different network scenarios, reducing the overall number of configurations needed while maintaining comprehensive security coverage across diverse situations.
Data Source
AI summary
A computer may receive editing instructions that specify one or more changes to filters in an existing access control list or a template for an access control list. Then, the computer may dynamically generate the clone access control list by applying the editing instructions to the existing access control list or the template for the access control list. For example, the computer may provide the editing instructions to a computer network device (such as a switch or a router) that are applied to the existing access control list or the template for the access control list while the computer network device is processing data packets. Alternatively, the computer may apply the editing instructions to the existing access control list or the template for the access control list that is not currently installed on the computer network device, and may provide the access control list to the computer network device.


