Dynamic Policy Provisioning via Authentication Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication protocols, such as IEEE 802.1X, do not provide a method for dynamically provisioning clients with policy decisions or configuration information without requiring full network access or relying on a central authentication server, limiting the ability to enforce complex access rules and service quality levels dynamically.

Innovation Solution

A method and system that involve receiving information from a client for determining network access policy, routing it through a network access device to an authentication server, and securely pushing the policy decision to the client via an encryption tunnel, allowing for dynamic provisioning of policy and configuration information before network access is granted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dynamic provisioning of policy decisions to clients is implemented, then network flexibility and security are enhanced, but network access requirements and system complexity increase

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidprovisioning system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing an encryption tunnel and authenticating the client before provisioning policy decisions. The authentication server pushes policy information to the client through the authenticated channel before the client gains full network access, ensuring security requirements are met while enabling dynamic provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an authentication server as an intermediary between the network access device and the client. The server receives authentication information, establishes secure channels, and mediates the provisioning of policy decisions, thereby managing system complexity centrally while enabling distributed policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If policy decisions are pushed to clients before network access is granted, then access control security is improved, but network access requirements become more stringent

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication and establishes an encryption tunnel before pushing policy decisions to the client. This ensures that policy provisioning occurs in a secure environment before network access is granted, maintaining high security standards while automating the process to preserve ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The client actively participates in the authentication process by providing authentication information and receiving policy decisions through the authenticated channel. This self-service approach allows the client to obtain policy provisioning without manual intervention while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption tunnels are established for secure communication, then communication security is enhanced, but system complexity and resource requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server acts as an intermediary that manages the establishment and maintenance of encryption tunnels. By centralizing the cryptographic operations and channel management on the server side, the client device complexity is reduced while maintaining high communication security through server-side cryptographic expertise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8051464B2Method for provisioning policy on user devices in wired and wireless networks
Publication Date: 2011.11.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8051464B2 patent drawing
  • US8051464B2 patent drawing
  • US8051464B2 patent drawing

AI summary

A method for provisioning client devices securely and automatically by means of a network provisioning system is disclosed. Provisioning occurs before the client is granted access to the network. The provisioning is determined dynamically at the time a client connects to the network and may depend on a multitude of factors specified by data dictionaries of the provisioning system.