Independent Role Based Authorization for Network Boundary Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions, particularly at boundary interface elements, lack independent control and auditing capabilities, leading to vulnerabilities and misaligned security policies between service providers and customers, which can result in unauthorized access and compromised network integrity.

Innovation Solution

Implementing an Independent Role Based Authorization (IRBA) system for network boundary interface elements, which includes a supervisory module and interface administrators to enable network administrators to configure and manage policies independently for each interface, ensuring exclusive control and visibility while restricting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If shared control and access are implemented at boundary interface elements, then network operations can be managed collaboratively, but security vulnerabilities and unauthorized access risks increase due to misaligned security policies

Engineering Contradiction:
Improvecollaborative management capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the boundary interface element into multiple independent administrative domains, each with its own security policy and access control rules. This allows different network administrators to manage their respective interfaces independently while maintaining overall system security through structured separation of authorities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary administrative framework that mediates between different network administrators' security policies. This intermediary layer ensures that collaborative operations can proceed while maintaining security boundaries, preventing direct access conflicts and policy misalignments between administrating parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If one network administrator is given full access to configure policies at the boundary interface, then configuration simplicity is improved, but security control and auditing capabilities deteriorate

Engineering Contradiction:
Improvepolicy configuration simplicityVSAvoidsecurity control and auditing
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides administrative authority into segmented roles, where different administrators have configured access rights to different interface segments. This segmentation maintains operational simplicity for each administrator while collectively providing comprehensive security control and auditing across all interfaces through the structured division of responsibilities.

Inventive Principle:
Principle #1Segmentation

3Reliability

If back-to-back firewalls are deployed to maintain exclusive control, then security control is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity controlVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple firewall functions and administrative controls into a single boundary interface element. This consolidation maintains the security control benefits of having multiple administrative perspectives while reducing the complexity and cost associated with deploying and managing separate back-to-back firewall systems.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If service providers are given unlimited access to customer networks for management, then service delivery is improved, but network security and customer control deteriorate

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by granting service providers access rights that are specific to particular interface segments and operational contexts. This allows service delivery efficiency to be maintained in areas where provider access is needed, while customer network security is preserved in areas where access is restricted, creating differentiated access zones within the network infrastructure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8272029B2Independent role based authorization in boundary interface elements
Publication Date: 2012.09.18 AT&T INTELLECTUAL PROPERTY I L P
  • US8272029B2 patent drawing
  • US8272029B2 patent drawing
  • US8272029B2 patent drawing

AI summary

A boundary interface element for communications networks is disclosed. The boundary interface element is adapted for enabling a network administrator for a first network coupled to a first network interface of the boundary interface element to configure a policy for the first network interface independently of the other administrators of the other interfaces, while restricting access to a second network interface of the boundary interface element. Similarly, the boundary interface element enables a network administrator for a second network coupled to the second network interface of the boundary interface element to configure a policy for the second network interface while restricting access to the first network interface. The network administrator for the first network is permitted to view the policy configured for the second network interface, and the network administrator for the second network is permitted to view the policy configured for the first network interface. The boundary interface element may be employed in a variety of network deployment scenarios.