Network Authorization Status Notification via AAA Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems face challenges in efficiently managing authorization status, particularly in establishing trust relationships between devices and networks, often requiring multiple message exchanges and lacking comprehensive authorization information during authentication, which can lead to unclear access permissions and potential security vulnerabilities.

Innovation Solution

The implementation of an authorization management component within AAA servers, network access devices, and application servers that enables real-time monitoring and notification of authorization status, allowing clients to query and receive comprehensive authorization information, including access levels and service permissions, both within and outside the authentication exchange, using cryptographic protection and machine learning for automated actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional network security systems use initial authentication by PE devices during network admission control, then network entity authentication is established, but authorization status information is not provided to clients, resulting in unclear access permissions and multiple message exchanges

Engineering Contradiction:
Improveauthorization status informationVSAvoidmessage exchange complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the authenticator determine and store authorization status information in advance during the authentication process. This pre-determined information is then made available to clients through a query mechanism, eliminating the need for multiple subsequent message exchanges to clarify access permissions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the authenticator acts as a mediator between the authentication system and clients. The authenticator stores and manages authorization status information, and clients can query this information through a standardized interface, reducing direct communication complexity between multiple system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security systems require multiple message exchanges to establish trust relationships, then comprehensive authorization information can be obtained, but the authentication process becomes time-consuming and complex

Engineering Contradiction:
Improvetrust relationship establishmentVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by determining authorization status information during the initial authentication process rather than requiring separate verification exchanges. The authenticator prepares and stores this information in advance, making it immediately available to clients who need to establish trust relationships, thereby reducing authentication time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If clients lack comprehensive authorization information during authentication, then authentication exchange is simplified, but access permissions become unclear and security vulnerabilities arise

Engineering Contradiction:
Improveauthentication exchange simplicityVSAvoidaccess permission clarity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary query mechanism where clients can obtain comprehensive authorization information from the authenticator through a standardized interface. This intermediary step maintains the simplicity of the initial authentication exchange while providing clients with the detailed authorization information needed for clear access permission understanding and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8381268B2Network authorization status notification
Publication Date: 2013.02.19 CISCO TECHNOLOGY INC
  • US8381268B2 patent drawing
  • US8381268B2 patent drawing
  • US8381268B2 patent drawing

AI summary

A system that enables network authorization status to be conveyed to the device requesting network services within or outside the scope of an authentication exchange is provided. The authorization status notification or information can be automatically generated or otherwise triggered by a request from the user or device. For instance, a query can be employed to solicit device authorization status related to a particular service or group of services. Additionally, authorization status notification can be automatically triggered based upon a change in the device authorization state.