Dynamic Rank Authorization for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems rely on static authorization, which is inefficient and resource-intensive, as it requires reauthentication for changes and does not adapt to dynamic network conditions, such as endpoint vulnerabilities or changes in security posture.
Innovation Solution
Implementing Dynamic Rank Authorization (DRA), where a policy server generates a ranked stack of authorization policies that can be dynamically applied and adjusted by an enforcement node based on real-time conditions, allowing for promotion or demotion of endpoint access levels without reauthentication, thereby reducing the need for global health checks and minimizing traffic between the policy server and enforcement node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static authorization is used, then network security is maintained through reauthentication, but network processing resources and bandwidth are consumed
Solution Approach 1:
The patent implements dynamic authorization that automatically adjusts access levels based on real-time endpoint compliance status. The system transitions from static reauthentication to dynamic policy adjustment, where endpoints are assigned to different authorization levels (e.g., Level 1 for non-compliant, Level 2 for compliant) and automatically promoted or demoted based on health check results, eliminating the need for manual reauthentication while maintaining security
Solution Approach 2:
The enforcement node performs local health checks and automatically enforces authorization level changes without requiring policy server involvement for each status change. The system enables self-service by allowing the enforcement node to independently evaluate endpoint compliance and adjust authorization levels, reducing traffic to the policy server and improving processing efficiency
2Reliability
If reauthentication is performed for authorization changes, then security is maintained, but network bandwidth and processing resources are consumed
Solution Approach 1:
The patent segments the authorization system into multiple independent authorization levels (Level 1, Level 2, etc.), each with specific access permissions. This segmentation allows the system to grant or revoke specific access levels without requiring complete reauthentication, as each level can be independently assigned based on endpoint compliance status, reducing the overhead of full reauthentication processes
Solution Approach 2:
The system performs preliminary health checks and authorization level assignments during initial endpoint registration. By pre-establishing authorization levels and compliance criteria, the system avoids the need for repeated reauthentication when authorization changes are needed, as endpoints can be automatically promoted or demoted based on pre-defined health check results
3Ease of operation
If static authorization policies are enforced, then network access control is simplified, but the system cannot adapt to changing security conditions
Solution Approach 1:
The patent implements a feedback mechanism where the enforcement node continuously monitors endpoint compliance status through health checks and automatically adjusts authorization levels based on the results. This closed-loop feedback system enables the network to dynamically adapt to changing security conditions, automatically promoting compliant endpoints to higher authorization levels and demoting non-compliant ones, maintaining both ease of operation and adaptability
Data Source
AI summary
In one embodiment, a method includes receiving at an enforcement node, a request to access a network from an endpoint, transmitting at the enforcement node, the access request to a policy server, receiving at the enforcement node from the policy server, a dynamic authorization comprising a plurality of ranks, each of the ranks comprising a policy for access to the network by the endpoint, assigning the endpoint to one of the ranks and applying the policy associated with the rank to traffic received from the endpoint at the enforcement node during a communication session between the endpoint and the network, assigning the endpoint to a different rank, and applying the policy associated with the rank to traffic received from the endpoint during the communication session. An apparatus and logic are also disclosed herein.


