NETCONF Shared Data Node Ownership for Granular NACM Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
NETCONF access control model (NACM) rules do not support efficient sharing of data nodes across multiple NETCONF clients with granular client controls, permissions, and privileges, leading to inefficiencies and security vulnerabilities in Open Radio Access Network (O-RAN) systems.
Innovation Solution
Introduce additional resource management operations such as Create-and-Own, Update-and-Own, Change-Ownership, and Relinquish-Ownership, along with enhanced CRUDX operations, to manage shared resource ownership securely and efficiently in O-RAN systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional NACM rules are used to manage NETCONF clients, then basic access control is provided, but granular control over shared data nodes and ownership management is insufficient
Solution Approach 1:
The patent segments the access control model into distinct ownership layers. Each NETCONF client is assigned a unique owner ID that segments the control authority over specific data nodes. This segmentation enables granular permission management where different clients can have different levels of access (read, write, delete, execute) to different data nodes, resolving the contradiction between ease of shared resource management and security control reliability.
Solution Approach 2:
The patent implements local quality by allowing different permission attributes to be assigned to different data nodes based on their ownership. Each data node can have its own access control list specifying which owner IDs have what permissions. This localized permission assignment enables precise control over shared resources, improving both the ease of operation for resource sharing and the reliability of security controls.
2Productivity
If data nodes are shared across multiple NETCONF clients, then resource utilization efficiency is improved, but tracking ownership and managing permissions becomes complex
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of owner IDs that mediate between multiple NETCONF clients and shared data nodes. Instead of directly managing complex permission matrices between clients and resources, the system uses owner IDs as intermediaries that simplify the tracking and management process. The NETCONF server mediates all access requests by verifying owner IDs and associated permissions, reducing the complexity of ownership tracking while enabling efficient resource sharing.
Solution Approach 2:
The owner ID mechanism serves multiple functions simultaneously: it identifies the client, establishes ownership, and controls access permissions. This multi-functionality reduces the complexity of ownership tracking by consolidating multiple management tasks into a single identifier system, thereby improving resource utilization efficiency without proportionally increasing system complexity.
3Reliability
If owner IDs are stored in each data node instance, then ownership tracking is maintained, but storage space is consumed and performance is reduced
Solution Approach 1:
The patent uses a copying approach where the owner ID is stored in the data node instance, but the actual permission details are copied from a centralized permission database. This allows ownership tracking to be maintained at the data node level with minimal storage overhead, while the comprehensive permission information is managed centrally and copied as needed during access operations. This resolves the contradiction by maintaining reliable ownership tracking without proportionally increasing storage space consumption.
4Ease of operation
If NACM rules are enhanced with additional operations, then granular control is achieved, but the existing NACM framework requires modification
Solution Approach 1:
The patent applies preliminary action by pre-defining a set of standardized operations (create-and-own, update-and-own, change-ownership, relinquish-ownership) that can be integrated into the NACM framework. These pre-defined operations provide granular control capability without requiring complex custom logic to be developed for each scenario. By preparing these operations in advance, the framework achieves enhanced functionality while managing complexity through standardization.
Data Source
AI summary
Systems and methods for handling and/or managing permissions data nodes across multiple NETCONF clients by generating or obtaining, by a NETCONF client, a first identifier, wherein the first identifier uniquely identifies the NETCONF client, establishing a first NETCONF session between a NETCONF server and the NETCONF client, wherein the NETCONF server comprises a first O-RU, wherein the NETCONF client comprises a first O-DU, delivering, from the NETCONF client to the NETCONF server, a first request during a NETCONF session handshake comprising the first identifier, delivering, from the NETCONF client to the NETCONF server, a first edit configuration request or payload, wherein the first edit configuration request or payload comprises the first identifier.


