Network Authentication With Dynamic Permission Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems rely on single authentication and authorization services that provide default network permissions, failing to meet the complex needs of modern, dynamic network environments.

Innovation Solution

A method and apparatus for network authentication involving an authentication server and a background server that dynamically determine network permissions based on user credentials and network scenarios, allowing for dynamic assignment of permissions and active refresh of network connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authentication and authorization service is used, then the system structure is simple, but it cannot meet the complex needs of modern network environments

Engineering Contradiction:
Improveadaptability to complex network environmentsVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is divided into two independent services: an authentication service (for verifying user credentials) and an authorization service (for managing network permissions). This segmentation allows each service to specialize in its function, enabling the system to handle complex network scenarios while maintaining clear separation of concerns and manageable complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If default network permission configurations are provided, then the authentication process is fast, but the permissions cannot be dynamically adjusted

Engineering Contradiction:
Improveauthentication speedVSAvoiddynamic permission adjustment capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The authorization service dynamically generates network permissions based on real-time authentication results and user profiles. Instead of using fixed default configurations, the system adapts permissions according to the specific authentication context, user roles, and network conditions, enabling both fast authentication and flexible permission management.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If network permissions are statically assigned, then the system is easy to manage, but it cannot adapt to changes in user permissions and network conditions

Engineering Contradiction:
Improvesystem management easeVSAvoidadaptation to permission changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authorization service implements a feedback mechanism that continuously monitors authentication results, user profile changes, and network conditions. Based on this feedback, the system automatically adjusts network permissions to match current requirements, maintaining both ease of management through automated processes and adaptability to changing conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12574365B2Method, apparatus, storage medium and electronic device for network authentication
Publication Date: 2026.03.10 BEIJING VOLCANO ENGINE TECH CO LTD
  • US12574365B2 patent drawing
  • US12574365B2 patent drawing
  • US12574365B2 patent drawing

AI summary

The present disclosure discloses methods, apparatuses, storage medium and electronic devices for network authentication. A first query request is sent to a background server through an authentication server, network permission information and a second user credential of a target user is sent by the background server to the authentication server in response to the first query request being received, and in the event that an authentication result obtained based on a first user credential and the second user credential characterizes that the authentication is passed, the authentication result and the network permission information are sent to a network device, causing the network device establish a communication connection between the network device and a terminal device. Thus, a network permission of the terminal device can be dynamically assigned based on a scenario in which the terminal device is located, and usage requirements of complex network authorization scenarios can be satisfied.