Network Device Intermediary for Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for techniques that allow a source device to be identified and authorized before allowing it to send packets to a destination device, without requiring the destination device or other network devices to know the network topology from which the packet was received.
Innovation Solution
A network device intercepts unauthorized data units, communicates with a policy server to establish authorization, and forwards authorized data units to the destination device, ensuring that only authorized communication occurs based on predefined network policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a source device is identified and authorized before allowing communication, then security and access control are improved, but device complexity and communication overhead increase due to interception and authorization verification processes
Solution Approach 1:
A network device is positioned as an intermediary between the source device and destination device. This intermediary intercepts data units, communicates with a policy server to obtain authorization information, and forwards authorized data units to the destination. This resolves the contradiction by centralizing the security verification function in a dedicated intermediary device, preventing the source and destination devices from needing complex built-in authorization logic.
Solution Approach 2:
The network device performs preliminary authorization verification by intercepting data units before they reach the destination and communicating with the policy server in advance. The policy server provides authorization information ahead of time, allowing the network device to pre-determine whether communication should be permitted. This preliminary action ensures security is established before actual data transmission occurs.
2Measurement precision
If authorization information is verified for each data unit, then access control precision is improved, but communication speed and productivity decrease due to repeated verification processes
Solution Approach 1:
The policy server generates authorization information that can be copied and reused for multiple data units from the same source device. Instead of performing full verification for each individual data unit, the network device uses the authorization information provided once by the policy server to make subsequent authorization decisions. This copying approach maintains precise access control while significantly improving communication speed.
3Ease of operation
If the destination device knows the network topology, then routing and access control are simplified, but security is reduced because topology information may reveal system architecture and access patterns
Solution Approach 1:
The network device acts as an intermediary that handles routing and authorization without requiring the destination device to know the source network's topology. The intermediary translates and forwards data units between different network domains, allowing the destination device to operate without topology knowledge while maintaining proper routing control through the intermediary's intelligent forwarding.
Data Source
AI summary
A device is configured to receive authorization information from a first network device and to receive a request that data units sent to a destination device contain authorization information, where the request is received from a second network device. The device is configured to assemble authorized data units by associating the authorization information with content intended for a destination device, where the content can be exchanged with the destination device during authorized communication. The device is configured to provide at least one of the authorized data units to the second network device so that the second network device can establish the authorized communication between the device and the destination device.


