Network Provisioning via NAC Fingerprint Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems lack the ability to provide fine-grained access control and policy application across multiple network resources, as they do not have access to fingerprint information of client devices, leading to inefficient and manual provisioning processes.
Innovation Solution
A network management system (NMS) that utilizes fingerprint information from a network access control (NAC) system to automate the provisioning of network resources, enabling fine-grained policy application and filtering by mapping client device identifiers to attributes and corresponding network resource policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network management systems use traditional authentication methods without fingerprint information, then the system complexity is low, but the ability to provide fine-grained access control and policy application is insufficient
Solution Approach 1:
The system segments network resource provisioning by creating distinct mappings between client device identifiers and specific network resources. Each client device can be associated with different network resources based on fingerprint attributes, enabling fine-grained control without requiring complete system redesign.
Solution Approach 2:
The patent introduces an intermediary mechanism that connects NAC systems with network management systems. This intermediary layer translates fingerprint information into actionable provisioning parameters, allowing fine-grained control while maintaining system modularity and managing complexity.
2Productivity
If network management systems manually provision network resources, then the provisioning process is simple to implement, but the productivity and efficiency of network management is low
Solution Approach 1:
The system performs preliminary actions by pre-establishing mappings between client device identifiers and network resources before actual network access is needed. Fingerprint information is collected and processed in advance, allowing automated provisioning decisions to be made quickly when devices connect to the network.
Solution Approach 2:
The patent implements self-service provisioning where the system automatically provisions network resources based on fingerprint information without requiring manual intervention. The automated mapping and provisioning processes enable the system to service itself, significantly improving productivity and reducing provisioning time.
3Adaptability or versatility
If network management systems lack access to fingerprint information, then the information processing requirements are low, but the ability to apply fine-grained policies across multiple network resources is limited
Solution Approach 1:
The patent merges fingerprint information from NAC systems with network management functions. By combining these previously separate information sources and functions, the system achieves fine-grained policy application across multiple network resources while ensuring that fingerprint information is effectively utilized rather than lost.
Data Source
AI summary
Techniques are described for providing network provisioning by a network management system (NMS) based on fingerprint information determined by a network access control (NAC) system. An example method includes receiving, by the NAC system, a network access request for a client device to access an enterprise network; obtaining, by the NAC system, fingerprint information of the client device associated with the network access request, wherein the fingerprinting information comprises information specifying one or more attributes associated with the client device; authenticating, by the NAC system, the client device to access the enterprise network; sending, by the NAC system and to the NMS, the fingerprint information of the client device; and provisioning, by the NMS, one or more network resources associated with the client device based on the fingerprint information of the client device.


