Network Device Intermediary for Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for techniques that allow a source device to be identified and authorized before allowing it to send packets to a destination device, without requiring the destination device or other network devices to know the network topology from which the packet was received.

Innovation Solution

A network device intercepts unauthorized data units, communicates with a policy server to establish authorization, and forwards authorized data units to the destination device, ensuring that only authorized communication occurs based on predefined network policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a source device is identified and authorized before allowing communication, then security and access control are improved, but device complexity and communication overhead increase due to interception and authorization verification processes

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A network device is positioned as an intermediary between the source device and destination device. This intermediary intercepts data units, communicates with a policy server to obtain authorization information, and forwards authorized data units to the destination. This resolves the contradiction by centralizing the security verification function in a dedicated intermediary device, preventing the source and destination devices from needing complex built-in authorization logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network device performs preliminary authorization verification by intercepting data units before they reach the destination and communicating with the policy server in advance. The policy server provides authorization information ahead of time, allowing the network device to pre-determine whether communication should be permitted. This preliminary action ensures security is established before actual data transmission occurs.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If authorization information is verified for each data unit, then access control precision is improved, but communication speed and productivity decrease due to repeated verification processes

Engineering Contradiction:
Improveaccess control precisionVSAvoidcommunication speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The policy server generates authorization information that can be copied and reused for multiple data units from the same source device. Instead of performing full verification for each individual data unit, the network device uses the authorization information provided once by the policy server to make subsequent authorization decisions. This copying approach maintains precise access control while significantly improving communication speed.

Inventive Principle:
Principle #26Copying

3Ease of operation

If the destination device knows the network topology, then routing and access control are simplified, but security is reduced because topology information may reveal system architecture and access patterns

Engineering Contradiction:
Improverouting controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network device acts as an intermediary that handles routing and authorization without requiring the destination device to know the source network's topology. The intermediary translates and forwards data units between different network domains, allowing the destination device to operate without topology knowledge while maintaining proper routing control through the intermediary's intelligent forwarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8185642B1Communication policy enforcement in a data network
Publication Date: 2012.05.22 PULSE SECURE LLC
  • US8185642B1 patent drawing
  • US8185642B1 patent drawing
  • US8185642B1 patent drawing

AI summary

A device is configured to receive authorization information from a first network device and to receive a request that data units sent to a destination device contain authorization information, where the request is received from a second network device. The device is configured to assemble authorized data units by associating the authorization information with content intended for a destination device, where the content can be exchanged with the destination device during authorized communication. The device is configured to provide at least one of the authorized data units to the second network device so that the second network device can establish the authorized communication between the device and the destination device.