Intent-Based Authorization for Dynamic Network Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems lack efficient dynamic authorization mechanisms to manage access to application capabilities based on user roles, leading to static and inflexible configuration processes.

Innovation Solution

Implementing intent-based authorization techniques that dynamically configure authorization information using intents, allowing for rapid deployment and management of access rights across multiple network devices based on user roles, by processing intents to determine and grant or deny access to application capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static configuration processes are used to manage access rights, then configuration stability is maintained, but adaptability to new applications and dynamic role changes deteriorates

Engineering Contradiction:
Improveadaptability to new applicationsVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization by allowing authorization information to be defined through intents that can be rapidly deployed and modified. The system dynamically configures authorization information to capabilities of applications based on user roles, enabling adaptability to new applications without static preconfiguration. This resolves the contradiction by making the authorization system flexible and responsive to changing requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses intent-based configuration where authorization rules are defined in advance as intents that can be rapidly deployed. These pre-defined intents capture authorization requirements before applications are deployed, enabling quick adaptation to new applications while maintaining structured management. The preliminary definition of authorization patterns simplifies the configuration process for dynamic scenarios.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If dynamic authorization configuration is implemented, then adaptability to new applications improves, but system complexity increases

Engineering Contradiction:
Improveflexibility in authorization managementVSAvoidauthorization system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer that translates high-level intent definitions into detailed authorization configurations. This intermediary processing layer manages the complexity by abstracting the authorization logic, allowing flexible intent-based configuration without exposing the underlying system complexity. The intermediary handles the mapping between user roles, capabilities, and authorization rules centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal intent-based authorization framework that can handle multiple applications and user roles through a common mechanism. This universal approach reduces complexity by providing a single, flexible authorization system that works across diverse applications rather than requiring separate configurations for each application-capability-user combination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If traditional static authorization is used, then system simplicity is maintained, but deployment speed of new authorization information deteriorates

Engineering Contradiction:
Improvedeployment speedVSAvoidauthorization configuration ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent uses template-based intent definitions that can be copied and reused across multiple applications and user roles. These authorization templates capture common authorization patterns that can be rapidly replicated, enabling fast deployment of new authorization information without recreating configurations from scratch. This copying mechanism accelerates deployment while maintaining operational simplicity.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If centralized static authorization storage is used, then configuration consistency is ensured, but scalability to new applications deteriorates

Engineering Contradiction:
ImprovescalabilityVSAvoidauthorization information consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic authorization information that can be rapidly updated and deployed across the system. Instead of static centralized storage, the system uses dynamic intent-based configurations that can adapt to new applications while maintaining consistency through centralized intent management. This dynamic approach enables scalability without sacrificing consistency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the system processes authorization requests and validates them against defined intents. This feedback loop ensures that authorization information remains consistent with the defined authorization patterns while allowing scalable adaptation to new applications. The feedback mechanism maintains reliability by validating authorization decisions against the intent definitions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11792071B1Intent-based user authentication for dynamic applications
Publication Date: 2023.10.17 JUNIPER NETWORKS INC
  • US11792071B1 patent drawing
  • US11792071B1 patent drawing

AI summary

An example computing system includes one or more processing units implemented in circuitry and configured to: process an intent for configuration of a plurality of managed network devices, the intent representing authorization of access to capabilities of applications accessible to users of the managed network devices according to roles assigned to the users; receive advertised capabilities from a new application accessible to the users; receive a request for authorization to one of the capabilities of the new application from one of the users; determine one of the roles assigned to the one of the users; determine whether the intent grants authorization to the one of the capabilities according to the one of the roles; and grant the one of the users access to the one of the capabilities when the intent grants authorization to the one of the capabilities according to the one of the roles.