Dynamic Access Control List Generation via Policy Enforcement Point Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access control systems in large IP networks face challenges due to manual management of access control lists (ACLs), leading to errors and maintenance issues, as spatial relationships between ACLs are not explicitly connected to the services they protect, and changes in services do not affect the ACLs accordingly.

Innovation Solution

A method and system for dynamically creating network access control lists using resource descriptions and policy enforcement point graphs to generate ACLs, which includes identifying paths between computing devices, discarding unauthorized paths, and generating ACLs based on permitted and desired access information to control network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management and creation of ACLs is used in large IP networks, then ACL configuration can be performed with existing tools, but numerous errors and maintenance issues occur due to the large number of ACLs and lack of explicit connection to services

Engineering Contradiction:
ImproveACL configuration accuracyVSAvoidACL management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by having the network device automatically generate ACL entries based on observed traffic flows. The device monitors traffic patterns and autonomously creates appropriate ACL rules without requiring manual intervention, thereby reducing errors while managing large numbers of ACLs efficiently

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the network device continuously monitors traffic flows and uses this information to dynamically adjust and update ACL configurations. This closed-loop approach ensures ACLs remain aligned with actual service requirements, reducing maintenance issues while handling network complexity

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If manual ACL changes are performed by the ACL management team, then ACL updates can be made, but significant opportunities for error occur because team members may forget that a particular traffic flow is possible

Engineering Contradiction:
ImproveACL update flexibilityVSAvoidACL configuration accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system replaces the mechanical manual process of ACL configuration with an automated electronic system. The network device automatically generates and updates ACL entries based on observed traffic flows, eliminating human memory limitations and errors while maintaining the flexibility to adapt to changing network conditions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of manufacture

If traditional manually configured ACLs are used, then ACLs can be created with basic tools, but they bear no explicit connection to the service or environment they are tasked to protect, leading to significant ACL maintenance issues

Engineering Contradiction:
ImproveACL creation easeVSAvoidACL maintenance ease
Core Design Contradiction:
Ease of manufactureVSEase of repair

Solution Approach 1:

The system transforms static manually-configured ACLs into dynamic automatically-generated ACLs. The ACL entries are continuously updated based on real-time traffic flow observations, ensuring they remain aligned with current service requirements. This dynamic approach simplifies maintenance by eliminating the need for manual updates while preserving ease of initial deployment

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary action by pre-generating ACL entries based on observed traffic patterns before manual intervention is needed. The network device proactively creates and updates ACL rules in advance, ensuring security policies are already in place and aligned with service requirements before maintenance issues can arise

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11750614B2Methods and systems for dynamic creation of access control lists
Publication Date: 2023.09.05 GOOGLE LLC
  • US11750614B2 patent drawing
  • US11750614B2 patent drawing
  • US11750614B2 patent drawing

AI summary

A method for dynamically creating network access control lists includes, by a processor receiving a request for an access control list (ACL). The method further includes, in response to receiving the request for the ACL: receiving a plurality of resource description from a first data source, receiving a policy enforcement point (PEP) graph for a network from a second data source, and using the plurality of resource descriptions and the PEP graph to generate the ACL, wherein the ACL comprises at least one policy for controlling network traffic through a PEP of the network. Each of the plurality of resource descriptions is associated with a plurality of computing devices in the network, and includes one or more of the following: information corresponding to an Internet Protocol definition of a computing device, information corresponding to desired access of the computing device, and information corresponding to permitted access of the computing device.