Host-Based Access Control Policy Generation for Scalable Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale networks face challenges in scalability and security, particularly in managing access control across distributed and heterogeneous environments, where existing solutions often compromise on usability, throughput, and maintenance due to the burden of policing access restrictions.
Innovation Solution
Implementing a method that defines security zones and roles for hosts in a network, forming access control policies based on role associations, and using an access rule formation engine to generate non-redundant policies for distributed access control, thereby allowing secure access while reducing the burden on network infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control methods are used in large-scale networks, then security can be maintained at individual nodes, but the complexity of managing access control policies increases significantly
Solution Approach 1:
The patent segments the network into security zones and hosts into roles, creating a hierarchical structure where access control policies are defined at the zone and role level rather than individually for each host pair. This segmentation reduces the overall complexity of access control management in large-scale networks.
Solution Approach 2:
The patent creates universal access control policies that apply to all hosts within a security zone based on their role assignments. Instead of creating unique policies for each host, a single policy can govern access for multiple hosts sharing the same role, reducing management overhead and complexity.
2Reliability
If strict access control policies are enforced across all hosts, then network security is improved, but the burden on network infrastructure and hosts increases
Solution Approach 1:
The patent applies different security policies to different security zones based on their specific security requirements. Rather than enforcing uniform strict policies across the entire network, each zone can have appropriately tailored access control rules, reducing unnecessary overhead on hosts and networks while maintaining security where needed.
3Reliability
If access control policies are customized for each host, then precise security control is achieved, but the time and resources required for policy creation and maintenance increase
Solution Approach 1:
The patent enables universal access control policies to be applied to multiple hosts simultaneously based on their role assignments. A single policy definition can govern access for all hosts in a particular role, dramatically reducing the time and resources required for policy creation and maintenance while maintaining precise security control through role-based granularity.
Solution Approach 2:
The patent merges individual host access control requirements into consolidated zone-level policies. By combining multiple individual policy requirements into a single unified policy at the security zone level, the system reduces the number of policies that need to be created, managed, and maintained.
4Adaptability or versatility
If distributed access control is implemented across multiple physical locations, then network scalability is improved, but the difficulty of maintaining security homogeneity increases
Solution Approach 1:
The patent implements universal access control policies that can be deployed across multiple physical locations and security zones. These universal policies ensure security homogeneity across the distributed network while allowing the network to scale to accommodate new locations and hosts without increasing management complexity.
Data Source
AI summary
Securing large networks having heterogeneous computing resources including provision of multiple services both to clients within and outside of the network, multiple sites, security zones, and other characteristics is provided using access control functionality implemented at hosts within the network. The access control functionality includes respective access control policies for indicating to each host from which other computers it can accept connections. Content of the access control policies can be determined based on application data flow needs, and can draw information from databases including DNS and security zone information for hosts to which the access control policies will be applied. Access control policies can be formatted automatically for different host with different characteristics from the same base logical rule set. Other aspects include using more permissive and/or access control rules provided on network equipment to block known bad data, while providing host-based access control focused on application data flow.


