Intent-Based Authorization for Dynamic Network Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems lack efficient dynamic authorization mechanisms to manage access to application capabilities based on user roles, leading to static and inflexible configuration processes.
Innovation Solution
Implementing intent-based authorization techniques that dynamically configure authorization information using intents, allowing for rapid deployment and management of access rights across multiple network devices based on user roles, by processing intents to determine and grant or deny access to application capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static configuration processes are used to manage access rights, then configuration stability is maintained, but adaptability to new applications and dynamic role changes deteriorates
Solution Approach 1:
The patent implements dynamic authorization by allowing authorization information to be defined through intents that can be rapidly deployed and modified. The system dynamically configures authorization information to capabilities of applications based on user roles, enabling adaptability to new applications without static preconfiguration. This resolves the contradiction by making the authorization system flexible and responsive to changing requirements.
Solution Approach 2:
The patent uses intent-based configuration where authorization rules are defined in advance as intents that can be rapidly deployed. These pre-defined intents capture authorization requirements before applications are deployed, enabling quick adaptation to new applications while maintaining structured management. The preliminary definition of authorization patterns simplifies the configuration process for dynamic scenarios.
2Adaptability or versatility
If dynamic authorization configuration is implemented, then adaptability to new applications improves, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary layer that translates high-level intent definitions into detailed authorization configurations. This intermediary processing layer manages the complexity by abstracting the authorization logic, allowing flexible intent-based configuration without exposing the underlying system complexity. The intermediary handles the mapping between user roles, capabilities, and authorization rules centrally.
Solution Approach 2:
The patent creates a universal intent-based authorization framework that can handle multiple applications and user roles through a common mechanism. This universal approach reduces complexity by providing a single, flexible authorization system that works across diverse applications rather than requiring separate configurations for each application-capability-user combination.
3Productivity
If traditional static authorization is used, then system simplicity is maintained, but deployment speed of new authorization information deteriorates
Solution Approach 1:
The patent uses template-based intent definitions that can be copied and reused across multiple applications and user roles. These authorization templates capture common authorization patterns that can be rapidly replicated, enabling fast deployment of new authorization information without recreating configurations from scratch. This copying mechanism accelerates deployment while maintaining operational simplicity.
4Adaptability or versatility
If centralized static authorization storage is used, then configuration consistency is ensured, but scalability to new applications deteriorates
Solution Approach 1:
The patent implements dynamic authorization information that can be rapidly updated and deployed across the system. Instead of static centralized storage, the system uses dynamic intent-based configurations that can adapt to new applications while maintaining consistency through centralized intent management. This dynamic approach enables scalability without sacrificing consistency.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system processes authorization requests and validates them against defined intents. This feedback loop ensures that authorization information remains consistent with the defined authorization patterns while allowing scalable adaptation to new applications. The feedback mechanism maintains reliability by validating authorization decisions against the intent definitions.
Data Source
AI summary
An example computing system includes one or more processing units implemented in circuitry and configured to: process an intent for configuration of a plurality of managed network devices, the intent representing authorization of access to capabilities of applications accessible to users of the managed network devices according to roles assigned to the users; receive advertised capabilities from a new application accessible to the users; receive a request for authorization to one of the capabilities of the new application from one of the users; determine one of the roles assigned to the one of the users; determine whether the intent grants authorization to the one of the capabilities according to the one of the roles; and grant the one of the users access to the one of the capabilities when the intent grants authorization to the one of the capabilities according to the one of the roles.

