Link-Layer Routing Selector for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security and access control methods, particularly in computer networks, lack flexibility and effectiveness, as they primarily rely on application-layer techniques that can create additional problems and do not efficiently manage selective access and control of network resources.

Innovation Solution

Implementing a network device with a selector that chooses a group routing policy based on device or user information to route communications through link-layer routes, using a policy database to manage these policies and ensuring that routing is stateful and invisible to users, allowing for dynamic and secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application-layer authentication techniques are used, then network access control is achieved, but flexibility and network security are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from application-layer authentication to link-layer routing control, moving the security enforcement point to a lower network layer. This dimensional shift in the OSI model allows for more flexible and secure access control by implementing policies at the link layer rather than relying on application-layer techniques, thereby resolving the contradiction between security and flexibility

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a network device with a selector that acts as an intermediary between devices attempting to forward packets and the network routing system. This selector intercepts packets, evaluates device information against group routing policies, and directs traffic according to security policies, providing enhanced control and flexibility while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If link-layer routing with policy selection is implemented, then network security and access control are enhanced, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidrouting device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The routing device is segmented into distinct functional components: an input for receiving packets, a selector for choosing group routing policies based on device information, and an output for forwarding packets according to selected policies. This segmentation allows each component to perform its function independently, managing complexity through modular design while maintaining enhanced security capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The selector component serves multiple functions: it receives device information, evaluates multiple group routing policies, selects the appropriate policy based on device characteristics, and directs packet forwarding. This multi-functionality consolidates what could be multiple separate components into a single versatile unit, managing device complexity while providing comprehensive security control

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11595305B2Device information method and apparatus for directing link-layer communication
Publication Date: 2023.02.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11595305B2 patent drawing
  • US11595305B2 patent drawing
  • US11595305B2 patent drawing

AI summary

A network device has an input configured to receive a message relating to a given device attempting to forward one or more packets across a computer network. The message has given device information relating to the given device. In addition, the routing device also has a selector, operatively coupled with the input, configured to select (after receiving the given data) a given group routing policy from a plurality of group routing policies. Preferably, the selector is configured to select the given group routing policy as a function of the given device information. The routing device also has an output operatively coupled with the selector. The output is configured to cause routing of device communication across the network using link-layer routes specified by the given group routing policy.