Geolocation-Based Access Entitlement for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches fail to effectively manage access control for geographically dispersed networking devices due to complex data sovereignty requirements and the challenges posed by Virtual Private Networks (VPNs), which complicate adherence to region-specific laws and policies.

Innovation Solution

A system that determines the geographic location of networking devices and users, using Multi-Factor Authentication (MFA) and Software as a Service (SaaS) cloud-based access entitlement server to enforce access policies dynamically, assigning Location-Based Access Criticality (LBAC) labels and integrating with device managers to ensure compliance with data sovereignty rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access control approaches are used for geographically dispersed networking devices, then device management is simplified, but compliance with data sovereignty requirements cannot be ensured

Engineering Contradiction:
Improvecompliance with data sovereignty requirementsVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is segmented into multiple components: geographic location determination module, user parameter determination module, access policy identification module, and request evaluation module. Each component handles a specific aspect of the access control process, enabling compliance with data sovereignty requirements while maintaining manageable system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that acts as a mediator between users and networking devices. This intermediary evaluates access requests against geographic location, user parameters, and access policies before permitting or denying access, thereby ensuring data sovereignty compliance without requiring complex modifications to the networking devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If VPNs are used to access networking devices remotely, then user flexibility is improved, but adherence to region-specific data sovereignty laws becomes more difficult

Engineering Contradiction:
Improveuser access flexibilityVSAvoidadherence to region-specific laws
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control system implements feedback by continuously evaluating user geographic location and device location against access policies. When a user attempts to access a networking device through VPN or otherwise, the system provides feedback by permitting or denying access based on whether the access request complies with data sovereignty requirements, thereby maintaining both flexibility and legal adherence.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system is dynamic in that it adapts access decisions based on real-time geographic location determination and user parameter evaluation. Rather than static access control lists, the system dynamically assesses each access request against current location data and applicable policies, enabling flexible remote access while ensuring compliance with region-specific laws.

Inventive Principle:
Principle #15Dynamics

3Reliability

If geographic location determination is implemented for access control, then data sovereignty compliance is improved, but system processing time increases

Engineering Contradiction:
Improvedata sovereignty complianceVSAvoidaccess request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining cached geographic location data and user parameter information. When an access request is received, the system utilizes pre-determined location and parameter data rather than determining everything from scratch, significantly reducing processing time while maintaining data sovereignty compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11968211B2Controlling access entitlement for networking device data
Publication Date: 2024.04.23 CISCO TECHNOLOGY INC
  • US11968211B2 patent drawing
  • US11968211B2 patent drawing
  • US11968211B2 patent drawing

AI summary

Techniques are provided for controlling access entitlement for networking device data. In one example, a geographic location of a networking device is determined. A request to access data associated with the networking device is obtained from a user device. A user parameter of a user associated with the user device is determined. An access policy that controls access to the data based on the geographic location of the networking device and the user parameter is identified. The request to access the data is permitted or denied based on the geographic location of the networking device, the user parameter, and the access policy.