Dynamic Rank Authorization for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems rely on static authorization, which is inefficient and resource-intensive, as it requires reauthentication for changes and does not adapt to dynamic network conditions, such as endpoint vulnerabilities or changes in security posture.

Innovation Solution

Implementing Dynamic Rank Authorization (DRA), where a policy server generates a ranked stack of authorization policies that can be dynamically applied and adjusted by an enforcement node based on real-time conditions, allowing for promotion or demotion of endpoint access levels without reauthentication, thereby reducing the need for global health checks and minimizing traffic between the policy server and enforcement node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authorization is used, then network security is maintained through reauthentication, but network processing resources and bandwidth are consumed

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic authorization that automatically adjusts access levels based on real-time endpoint compliance status. The system transitions from static reauthentication to dynamic policy adjustment, where endpoints are assigned to different authorization levels (e.g., Level 1 for non-compliant, Level 2 for compliant) and automatically promoted or demoted based on health check results, eliminating the need for manual reauthentication while maintaining security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The enforcement node performs local health checks and automatically enforces authorization level changes without requiring policy server involvement for each status change. The system enables self-service by allowing the enforcement node to independently evaluate endpoint compliance and adjust authorization levels, reducing traffic to the policy server and improving processing efficiency

Inventive Principle:
Principle #25Self-service

2Reliability

If reauthentication is performed for authorization changes, then security is maintained, but network bandwidth and processing resources are consumed

Engineering Contradiction:
Improveauthorization securityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the authorization system into multiple independent authorization levels (Level 1, Level 2, etc.), each with specific access permissions. This segmentation allows the system to grant or revoke specific access levels without requiring complete reauthentication, as each level can be independently assigned based on endpoint compliance status, reducing the overhead of full reauthentication processes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary health checks and authorization level assignments during initial endpoint registration. By pre-establishing authorization levels and compliance criteria, the system avoids the need for repeated reauthentication when authorization changes are needed, as endpoints can be automatically promoted or demoted based on pre-defined health check results

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If static authorization policies are enforced, then network access control is simplified, but the system cannot adapt to changing security conditions

Engineering Contradiction:
Improveauthorization managementVSAvoidresponse to security changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the enforcement node continuously monitors endpoint compliance status through health checks and automatically adjusts authorization levels based on the results. This closed-loop feedback system enables the network to dynamically adapt to changing security conditions, automatically promoting compliant endpoints to higher authorization levels and demoting non-compliant ones, maintaining both ease of operation and adaptability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10171504B2Network access with dynamic authorization
Publication Date: 2019.01.01 CISCO TECHNOLOGY INC
  • US10171504B2 patent drawing
  • US10171504B2 patent drawing
  • US10171504B2 patent drawing

AI summary

In one embodiment, a method includes receiving at an enforcement node, a request to access a network from an endpoint, transmitting at the enforcement node, the access request to a policy server, receiving at the enforcement node from the policy server, a dynamic authorization comprising a plurality of ranks, each of the ranks comprising a policy for access to the network by the endpoint, assigning the endpoint to one of the ranks and applying the policy associated with the rank to traffic received from the endpoint at the enforcement node during a communication session between the endpoint and the network, assigning the endpoint to a different rank, and applying the policy associated with the rank to traffic received from the endpoint during the communication session. An apparatus and logic are also disclosed herein.