Dynamic Privilege Download for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems face inefficiencies in managing privilege setting definitions, as they require each network device to store all definitions, even if not in use, leading to unnecessary storage and resource utilization.

Innovation Solution

A system and method that dynamically downloads privilege setting definitions from an authentication server only for currently connected client devices and clears definitions no longer in use, optimizing storage and resource allocation by retrieving and deleting unused definitions based on client device associations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each network device stores all privilege setting definitions, then the system ensures complete privilege definitions are available for any client device, but the storage requirements and resource utilization increase unnecessarily

Engineering Contradiction:
Improveavailability of privilege definitionsVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the privilege setting definitions into two groups: those currently in use by connected client devices and those not in use. Network devices dynamically download only the segmented portion needed for current clients, rather than storing all definitions locally. This segmentation resolves the contradiction by maintaining availability of needed definitions while reducing storage requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic downloading and deletion of privilege setting definitions based on real-time client device connections. When client devices connect, the network device downloads the required privilege definitions; when clients disconnect, the definitions are deleted. This dynamic approach ensures definitions are available when needed while minimizing storage requirements, resolving the contradiction between reliability and quantity.

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If privilege setting definitions are downloaded dynamically based on client connections, then storage requirements are reduced, but the system complexity increases

Engineering Contradiction:
Improvestorage requirementsVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the network device automatically monitors client device connections, identifies which privilege setting definitions are needed, downloads them from the authentication server, and deletes them when no longer needed. This automated self-service approach reduces storage requirements while managing system complexity through automation rather than manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where the network device continuously monitors the connection status of client devices and adjusts its privilege setting definition storage accordingly. When clients connect, the system receives feedback about needed definitions and downloads them; when clients disconnect, feedback triggers deletion. This feedback mechanism resolves the contradiction by dynamically adapting storage to actual needs while managing complexity through automated responses.

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If all network devices store all privilege setting definitions, then updates can be applied uniformly across the network, but the processing overhead and time required for updates increases

Engineering Contradiction:
Improveconsistency of privilege definitionsVSAvoidupdate time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The patent segments the update distribution process to target only those network devices that currently have connected client devices requiring specific privilege definitions. Instead of broadcasting updates to all network devices uniformly, the system sends updates only to devices that need them based on current client connections. This segmented approach maintains consistency where needed while reducing update time and processing overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic update distribution based on real-time client connection status. Network devices dynamically receive and apply privilege definition updates only when they have connected client devices that require those definitions. When no clients are connected, updates are not applied or are deferred. This dynamic approach maintains stability of privilege definitions for active clients while significantly reducing update time and processing overhead by avoiding unnecessary updates to devices with no active connections.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10110702B2Dynamic download and enforcement of network access role based on network login context
Publication Date: 2018.10.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10110702B2 patent drawing
  • US10110702B2 patent drawing
  • US10110702B2 patent drawing

AI summary

Systems and methods are described that configure network devices to dynamically (1) download privilege setting definitions from an authentication server to address a currently connected set of client devices associated with these privilege setting definitions and (2) clear privilege setting definitions that are no longer in use by client devices connected to the network device. In particular, a network device may determine if a privilege setting definition associated with a successfully authenticated client device is locally available on the network device and request the privilege setting definition from the authentication server when not locally available. In some situations, the authentication server may selectively transmit update messages to network devices that may be affected by an update to a privilege setting definition such that the network devices may request this updated privilege setting definition for download.