Centralized Authorization Server for NETCONF Network Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing NETCONF authorization solution lacks centralized authorization capabilities, leading to slow network provisioning performance, especially in IoT environments where users need integrated authorization configurations across different network access points.

Innovation Solution

A centralized authorization solution for NETCONF is proposed, utilizing a network management device and a centralized authorization server with a remote authorization protocol like TACACS+, which enables integrated authorization information management without requiring identical authorization configurations across all network access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized authorization server is implemented, then network provisioning performance is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork provisioning performanceVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized authorization server as an intermediary component between network management devices and users. This server receives authorization requests from network management devices, queries authorization information from a database, and returns authorization decisions. This intermediary structure enables centralized control and improves network provisioning performance without requiring complex configuration changes at each network access point, thus resolving the contradiction between improved productivity and increased system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If identical authorization configurations are required across all network access points, then authorization consistency is improved, but configuration complexity and maintenance difficulty increase

Engineering Contradiction:
Improveauthorization consistencyVSAvoidconfiguration complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent implements a universal authorization server that serves multiple network management devices and various types of users (IoT devices, mobile phones, tablets, laptops) through a single centralized system. The server provides unified authorization management for diverse access points including WiFi, Bluetooth, and NFC interfaces. This universal approach ensures authorization consistency across all access points while eliminating the need for identical configurations at each device, thereby reducing configuration complexity and maintenance difficulty.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses a centralized authorization database that stores and manages authorization information for multiple users and devices. Instead of maintaining separate authorization configurations at each network access point, the system creates a centralized copy of authorization data that can be efficiently queried and updated. This copying approach ensures all access points access the same authorization information, maintaining consistency while simplifying configuration management through a single source of truth.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3721596B1Network management device and centralized authorization server for netconf
Publication Date: 2022.11.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3721596B1 patent drawingFigure 1
  • EP3721596B1 patent drawingFigure 2
  • EP3721596B1 patent drawingFigure 3~4

AI summary

A network management device and a centralized authorization server are disclosed for network configuration (NETCONF) protocol. The network management device comprises a management server component and an authorization client component. The management server component is configured, with NETCONF protocol, to process a user operation request from a management agent based at least on authorization information from the authorization client component. The authorization client component is configured, with a remote authorization protocol, to obtain, for the user operation request, the authorization information from the centralized authorization server.