Link-Layer Routing Policy Selector for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security and access control methods, particularly in computer networks, lack flexibility and effectiveness, as they rely on Application layer techniques that can create additional problems and do not efficiently manage selective access and tracking of network resources.

Innovation Solution

Implementing a network device with a selector that chooses a group routing policy based on user or device information, using link-layer routes to manage access and communication, thereby enabling stateful routing that is transparent to users and devices, and allowing for hierarchical policies to control access and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Application layer authentication techniques are used to control network access, then user authentication can be achieved, but network security and access control flexibility are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a link-layer authentication mechanism that operates as an intermediary between the physical network infrastructure and the Application layer protocols. This link-layer authentication (such as 802.1X) provides a foundation layer of security that works transparently with various Application layer protocols, thereby improving overall network security while maintaining flexibility in access control policies without requiring changes to Application layer implementations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Application layer techniques are used for access control, then authentication can be implemented, but the system becomes less effective and creates additional problems

Engineering Contradiction:
Improveauthentication implementationVSAvoidaccess control effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent moves the authentication mechanism from the Application layer down to the link layer, effectively changing the dimensional layer in the OSI model where authentication occurs. This link-layer authentication operates independently from Application layer protocols, providing a more reliable foundation for access control that doesn't depend on the complexities and variations of different Application layer implementations

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If traditional routing methods are used, then network communication can be established, but selective access control and tracking of network resources is inefficient

Engineering Contradiction:
Improvenetwork resource management efficiencyVSAvoidselective access control capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements quality-based routing where different link-layer quality of service (QoS) parameters are applied to different users or devices based on their authentication credentials and access policies. This allows selective access control where specific users can be directed to specific network paths or resources based on their authorization level, thereby improving both the efficiency of network resource management and the capability for selective access control

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11575577B2User information method and apparatus for directing link-layer communication
Publication Date: 2023.02.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11575577B2 patent drawing
  • US11575577B2 patent drawing
  • US11575577B2 patent drawing

AI summary

A network device has an input configured to receive a message relating to a given user attempting to forward one or more packets across a computer network. The message has given user information relating to the given user. In addition, the routing device also has a selector, operatively coupled with the input, configured to select (after receiving the message) a given group routing policy from a plurality of group routing policies. Preferably, the selector is configured to select the given group routing policy as a function of the given user information. The routing device also has an output operatively coupled with the selector. The output is configured to cause routing of user communication across the network using link-layer routes specified by the given group routing policy.