NETCONF Shared Data Node Ownership for Granular NACM Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

NETCONF access control model (NACM) rules do not support efficient sharing of data nodes across multiple NETCONF clients with granular client controls, permissions, and privileges, leading to inefficiencies and security vulnerabilities in Open Radio Access Network (O-RAN) systems.

Innovation Solution

Introduce additional resource management operations such as Create-and-Own, Update-and-Own, Change-Ownership, and Relinquish-Ownership, along with enhanced CRUDX operations, to manage shared resource ownership securely and efficiently in O-RAN systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional NACM rules are used to manage NETCONF clients, then basic access control is provided, but granular control over shared data nodes and ownership management is insufficient

Engineering Contradiction:
Improveshared resource managementVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access control model into distinct ownership layers. Each NETCONF client is assigned a unique owner ID that segments the control authority over specific data nodes. This segmentation enables granular permission management where different clients can have different levels of access (read, write, delete, execute) to different data nodes, resolving the contradiction between ease of shared resource management and security control reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different permission attributes to be assigned to different data nodes based on their ownership. Each data node can have its own access control list specifying which owner IDs have what permissions. This localized permission assignment enables precise control over shared resources, improving both the ease of operation for resource sharing and the reliability of security controls.

Inventive Principle:
Principle #3Local quality

2Productivity

If data nodes are shared across multiple NETCONF clients, then resource utilization efficiency is improved, but tracking ownership and managing permissions becomes complex

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidownership tracking complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of owner IDs that mediate between multiple NETCONF clients and shared data nodes. Instead of directly managing complex permission matrices between clients and resources, the system uses owner IDs as intermediaries that simplify the tracking and management process. The NETCONF server mediates all access requests by verifying owner IDs and associated permissions, reducing the complexity of ownership tracking while enabling efficient resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The owner ID mechanism serves multiple functions simultaneously: it identifies the client, establishes ownership, and controls access permissions. This multi-functionality reduces the complexity of ownership tracking by consolidating multiple management tasks into a single identifier system, thereby improving resource utilization efficiency without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If owner IDs are stored in each data node instance, then ownership tracking is maintained, but storage space is consumed and performance is reduced

Engineering Contradiction:
Improveownership trackingVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses a copying approach where the owner ID is stored in the data node instance, but the actual permission details are copied from a centralized permission database. This allows ownership tracking to be maintained at the data node level with minimal storage overhead, while the comprehensive permission information is managed centrally and copied as needed during access operations. This resolves the contradiction by maintaining reliable ownership tracking without proportionally increasing storage space consumption.

Inventive Principle:
Principle #26Copying

4Ease of operation

If NACM rules are enhanced with additional operations, then granular control is achieved, but the existing NACM framework requires modification

Engineering Contradiction:
Improvegranular control capabilityVSAvoidNACM framework complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining a set of standardized operations (create-and-own, update-and-own, change-ownership, relinquish-ownership) that can be integrated into the NACM framework. These pre-defined operations provide granular control capability without requiring complex custom logic to be developed for each scenario. By preparing these operations in advance, the framework achieves enhanced functionality while managing complexity through standardization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12627661B2Enhanced NETCONF access control model (NACM) operations and granular controls for shared data node management
Publication Date: 2026.05.12 RAKUTEN SYMPHONY INC
  • US12627661B2 patent drawing
  • US12627661B2 patent drawing
  • US12627661B2 patent drawing

AI summary

Systems and methods for handling and/or managing permissions data nodes across multiple NETCONF clients by generating or obtaining, by a NETCONF client, a first identifier, wherein the first identifier uniquely identifies the NETCONF client, establishing a first NETCONF session between a NETCONF server and the NETCONF client, wherein the NETCONF server comprises a first O-RU, wherein the NETCONF client comprises a first O-DU, delivering, from the NETCONF client to the NETCONF server, a first request during a NETCONF session handshake comprising the first identifier, delivering, from the NETCONF client to the NETCONF server, a first edit configuration request or payload, wherein the first edit configuration request or payload comprises the first identifier.