Host-Based Access Control Policy Generation for Scalable Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale networks face challenges in scalability and security, particularly in managing access control across distributed and heterogeneous environments, where existing solutions often compromise on usability, throughput, and maintenance due to the burden of policing access restrictions.

Innovation Solution

Implementing a method that defines security zones and roles for hosts in a network, forming access control policies based on role associations, and using an access rule formation engine to generate non-redundant policies for distributed access control, thereby allowing secure access while reducing the burden on network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used in large-scale networks, then security can be maintained at individual nodes, but the complexity of managing access control policies increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into security zones and hosts into roles, creating a hierarchical structure where access control policies are defined at the zone and role level rather than individually for each host pair. This segmentation reduces the overall complexity of access control management in large-scale networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal access control policies that apply to all hosts within a security zone based on their role assignments. Instead of creating unique policies for each host, a single policy can govern access for multiple hosts sharing the same role, reducing management overhead and complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If strict access control policies are enforced across all hosts, then network security is improved, but the burden on network infrastructure and hosts increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security policies to different security zones based on their specific security requirements. Rather than enforcing uniform strict policies across the entire network, each zone can have appropriately tailored access control rules, reducing unnecessary overhead on hosts and networks while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

3Reliability

If access control policies are customized for each host, then precise security control is achieved, but the time and resources required for policy creation and maintenance increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy creation and maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables universal access control policies to be applied to multiple hosts simultaneously based on their role assignments. A single policy definition can govern access for all hosts in a particular role, dramatically reducing the time and resources required for policy creation and maintenance while maintaining precise security control through role-based granularity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges individual host access control requirements into consolidated zone-level policies. By combining multiple individual policy requirements into a single unified policy at the security zone level, the system reduces the number of policies that need to be created, managed, and maintained.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If distributed access control is implemented across multiple physical locations, then network scalability is improved, but the difficulty of maintaining security homogeneity increases

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universal access control policies that can be deployed across multiple physical locations and security zones. These universal policies ensure security homogeneity across the distributed network while allowing the network to scale to accommodate new locations and hosts without increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8763074B2Scalable firewall policy management platform
Publication Date: 2014.06.24 R2 SOLUTIONS LLC
  • US8763074B2 patent drawing
  • US8763074B2 patent drawing
  • US8763074B2 patent drawing

AI summary

Securing large networks having heterogeneous computing resources including provision of multiple services both to clients within and outside of the network, multiple sites, security zones, and other characteristics is provided using access control functionality implemented at hosts within the network. The access control functionality includes respective access control policies for indicating to each host from which other computers it can accept connections. Content of the access control policies can be determined based on application data flow needs, and can draw information from databases including DNS and security zone information for hosts to which the access control policies will be applied. Access control policies can be formatted automatically for different host with different characteristics from the same base logical rule set. Other aspects include using more permissive and/or access control rules provided on network equipment to block known bad data, while providing host-based access control focused on application data flow.