IF-MAP Network Device Security Policy Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems face challenges in securely provisioning access to resources based on dynamic security policies, particularly in ensuring that endpoints communicate over secured links, which is not effectively managed by current IF-MAP frameworks.

Innovation Solution

The proposed solution involves a network device that subscribes to an IF-MAP server for updates on security policy parameters, receives and configures these parameters, and then transmits them to endpoints to establish secure communication links, ensuring compliance with security policies for accessing network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing IF-MAP frameworks are used for network access control, then basic identity and access control information can be stored and retrieved, but secure provisioning of access based on dynamic security policies cannot be effectively implemented

Engineering Contradiction:
Improvedynamic security policy provisioningVSAvoidsecure communication link establishment
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by having network devices subscribe to IF-MAP server updates before access requests occur. The system proactively receives and configures security policy parameters (such as IPsec settings) in advance, so that when an endpoint needs to access a resource, the secure communication link is already provisioned and ready, eliminating the need for reactive security configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the IF-MAP server acts as a mediator between the network device and the endpoint. The server publishes security policy updates that the network device subscribes to, and these updates are then transmitted to endpoints. This intermediary framework enables dynamic security policy provisioning while maintaining secure communication, resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network devices subscribe to IF-MAP server updates for security policy parameters, then dynamic security policy provisioning is enabled, but additional system complexity is introduced

Engineering Contradiction:
Improvesecurity policy parameter updatesVSAvoidsubscription and update management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a standardized IF-MAP subscription mechanism that serves multiple functions: receiving security policy updates, managing endpoint access control, and provisioning secure communication parameters. This multi-functional approach consolidates what would otherwise be separate complex systems into a unified framework, reducing overall device complexity while maintaining high adaptability for dynamic security policy provisioning.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8856909B1IF-MAP provisioning of resources and services
Publication Date: 2014.10.07 PULSE SECURE LLC
  • US8856909B1 patent drawing
  • US8856909B1 patent drawing
  • US8856909B1 patent drawing

AI summary

A method may include receiving a request from an endpoint to access a network; granting access to the network; and subscribing to an IF-MAP server for updates relating to the endpoint. The method may also include receiving an update pertaining to the endpoint, from the IF-MAP server; and transmitting the update to the endpoint. Additionally, a method may include receiving a request from an endpoint to access a resource in a network; denying the request from the endpoint based on a security policy; and subscribing or querying to an IF-MAP server for IF-MAP data pertaining to the endpoint. The method may also include receiving from the IF-MAP server the IF-MAP data; and publishing, by the device, to the IF-MAP server, IF-MAP data pertaining to the endpoint, where the IF-MAP data includes security policy parameters that comply with the security policy for accessing the resource.