Network Beacon Access Control via Dynamic Authorization Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control methods, such as access lists, are inadequate for managing dynamic groups of authorized client devices, particularly in transient relationships where the group of authorized devices frequently changes, such as in service provider-customer scenarios.

Innovation Solution

A system and method that utilize network beacons to authorize client devices by determining whether they satisfy specific authorization rules, allowing access only to those that meet the criteria and terminating access when these rules are no longer satisfied, thereby dynamically managing access rights based on device profiles and resource availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access lists are used to control network access, then network security is maintained for stable groups, but the system cannot adapt to frequently changing authorized device groups

Engineering Contradiction:
Improveadaptability to changing authorized device groupsVSAvoidcomplexity of access control management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by continuously evaluating client devices against authorization rules rather than using static access lists. The system dynamically adds or removes devices from authorized groups based on real-time rule satisfaction, enabling adaptation to changing relationships without manual reconfiguration of access lists.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the fundamental parameter of access control from fixed device identifiers (access lists) to dynamic rule-based criteria. Authorization rules can be modified to reflect changing relationships, and the system automatically reevaluates device authorization based on these parameter changes, enabling flexible adaptation to transient and evolving relationships.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If access lists are manually maintained, then authorized devices can be controlled, but administrative burden increases when groups frequently change

Engineering Contradiction:
Improveease of access control managementVSAvoidtime for updating access lists
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system implements self-service access control where client devices automatically evaluate themselves against authorization rules and receive appropriate access rights without manual administrator intervention. When relationships change, the system autonomously reevaluates and updates authorization status, eliminating the need for administrators to manually update access lists and significantly reducing administrative time and effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors relationship status between network and client devices and provides feedback by automatically adjusting access rights based on current authorization rule satisfaction. This closed-loop feedback mechanism ensures access control remains synchronized with actual relationships without requiring manual updates, greatly simplifying operations and reducing administrative time investment.

Inventive Principle:
Principle #23Feedback

3Productivity

If static access lists are used, then implementation is simple, but the system cannot respond to transient relationships

Engineering Contradiction:
Improvespeed of access authorizationVSAvoidability to handle transient relationships
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary evaluation of client devices against authorization rules before granting access. By pre-establishing comprehensive authorization rules that cover various relationship scenarios, the system can rapidly determine authorization status without manual intervention, enabling both fast response and high adaptability to transient relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically responds to transient relationships by continuously evaluating device authorization status based on current relationship conditions. When relationships change or terminate, the system automatically detects these changes and adjusts access rights in real-time, providing both rapid response to authorization requests and high adaptability to changing relationship dynamics.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10986095B2Systems and methods for controlling network access
Publication Date: 2021.04.20 OMNISSA LLC
  • US10986095B2 patent drawing
  • US10986095B2 patent drawing
  • US10986095B2 patent drawing

AI summary

A computing device obtains a request from a user device to access a network beacon. The computing device obtains a device profile for the user device. The computing device determines whether the user device satisfies an authorization rule based on the state of the user device as indicated by the device profile. The computing device authorizes the user device to access the network beacon responsive to determining that the user device satisfies the authorization rule.