Network Resources Discovery Proxy for Authorized Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network resources discovery systems in computer networks are limited by non-routing discovery packets, which restrict access to only connected subnets and fail to isolate resources to authorized users, leading to privacy issues in multi-user environments.
Innovation Solution
A network resources discovery system that employs a network resources discovery proxy to intermediate discovery packets and enforce matching rules, ensuring only authorized devices can access specific network services and devices, enhancing security and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-routing discovery packets are used for resource discovery, then devices can discover resources in connected subnets, but authorized users cannot be isolated from accessing resources they should not reach
Solution Approach 1:
The patent introduces a network resources discovery proxy as an intermediary component that sits between user devices and network subnets. This proxy receives discovery packets from user devices, applies authorization rules to determine which resources the user is permitted to access, and selectively forwards or blocks discovery requests accordingly. This intermediary mechanism enables both resource discovery functionality and security isolation without requiring changes to the underlying subnet architecture.
2Reliability
If multiple logically separate subnets are used to support different network services, then security and scalability are enhanced, but resource discovery becomes more complex and restricted
Solution Approach 1:
The network resources discovery proxy is designed as a universal intermediary that can handle discovery requests for multiple different subnets and service types through a single unified interface. It implements a rule-based authorization system that can dynamically determine access permissions across various network segments without requiring separate discovery mechanisms for each subnet, thereby simplifying the overall discovery process while maintaining security boundaries.
3Ease of operation
If discovery packets are sent directly to each subnet, then the discovery process is simple and direct, but users can access resources in subnets they are not authorized to reach
Solution Approach 1:
The discovery proxy serves as an intermediary that maintains the simplicity of the discovery process from the user's perspective while adding security enforcement in the background. User devices continue to send discovery requests in the standard manner, but the proxy intercepts these requests, applies authorization rules based on user credentials and subnet policies, and selectively forwards requests to appropriate subnets. This approach preserves ease of operation while preventing unauthorized resource access.
Data Source
AI summary
A network resources discovery system regulates the automated discovery of available network resources using a network-enabled device to ensure that the network-enabled device only discovers the specific network resources which it is authorized to access. In use, a network resources discovery proxy includes a local controller which intermediates network resources discovery request and response packets transmitted between the network-enabled device and available network resources. By comparing the network resources discovery packets against a local, modifiable set of matching rules, the network resources discovery proxy is able to filter out the automated discovery of any types of services and devices provided by a computer network which the network-enabled device is not permitted to receive. By restricting the automated discovery of network resources in accordance with the local set of matching rules, the network resources discovery system provides an enhanced level of network security through the selective isolation of network devices.


