Network Provisioning via NAC Fingerprint Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems lack the ability to provide fine-grained access control and policy application across multiple network resources, as they do not have access to fingerprint information of client devices, leading to inefficient and manual provisioning processes.

Innovation Solution

A network management system (NMS) that utilizes fingerprint information from a network access control (NAC) system to automate the provisioning of network resources, enabling fine-grained policy application and filtering by mapping client device identifiers to attributes and corresponding network resource policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network management systems use traditional authentication methods without fingerprint information, then the system complexity is low, but the ability to provide fine-grained access control and policy application is insufficient

Engineering Contradiction:
Improvefine-grained access control capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments network resource provisioning by creating distinct mappings between client device identifiers and specific network resources. Each client device can be associated with different network resources based on fingerprint attributes, enabling fine-grained control without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that connects NAC systems with network management systems. This intermediary layer translates fingerprint information into actionable provisioning parameters, allowing fine-grained control while maintaining system modularity and managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If network management systems manually provision network resources, then the provisioning process is simple to implement, but the productivity and efficiency of network management is low

Engineering Contradiction:
Improvenetwork provisioning efficiencyVSAvoidprovisioning time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing mappings between client device identifiers and network resources before actual network access is needed. Fingerprint information is collected and processed in advance, allowing automated provisioning decisions to be made quickly when devices connect to the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service provisioning where the system automatically provisions network resources based on fingerprint information without requiring manual intervention. The automated mapping and provisioning processes enable the system to service itself, significantly improving productivity and reducing provisioning time.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If network management systems lack access to fingerprint information, then the information processing requirements are low, but the ability to apply fine-grained policies across multiple network resources is limited

Engineering Contradiction:
Improvepolicy application granularityVSAvoidfingerprint information accessibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges fingerprint information from NAC systems with network management functions. By combining these previously separate information sources and functions, the system achieves fine-grained policy application across multiple network resources while ensuring that fingerprint information is effectively utilized rather than lost.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250047675A1Closed-loop network provisioning based on network access control fingerprinting
Publication Date: 2025.02.06 JUNIPER NETWORKS INC
  • US20250047675A1 patent drawing
  • US20250047675A1 patent drawing
  • US20250047675A1 patent drawing

AI summary

Techniques are described for providing network provisioning by a network management system (NMS) based on fingerprint information determined by a network access control (NAC) system. An example method includes receiving, by the NAC system, a network access request for a client device to access an enterprise network; obtaining, by the NAC system, fingerprint information of the client device associated with the network access request, wherein the fingerprinting information comprises information specifying one or more attributes associated with the client device; authenticating, by the NAC system, the client device to access the enterprise network; sending, by the NAC system and to the NMS, the fingerprint information of the client device; and provisioning, by the NMS, one or more network resources associated with the client device based on the fingerprint information of the client device.