Network Resources Discovery Proxy for Authorized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network resources discovery systems in computer networks are limited by non-routing discovery packets, which restrict access to only connected subnets and fail to isolate resources to authorized users, leading to privacy issues in multi-user environments.

Innovation Solution

A network resources discovery system that employs a network resources discovery proxy to intermediate discovery packets and enforce matching rules, ensuring only authorized devices can access specific network services and devices, enhancing security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-routing discovery packets are used for resource discovery, then devices can discover resources in connected subnets, but authorized users cannot be isolated from accessing resources they should not reach

Engineering Contradiction:
Improveresource discovery capabilityVSAvoidunauthorized access to resources
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network resources discovery proxy as an intermediary component that sits between user devices and network subnets. This proxy receives discovery packets from user devices, applies authorization rules to determine which resources the user is permitted to access, and selectively forwards or blocks discovery requests accordingly. This intermediary mechanism enables both resource discovery functionality and security isolation without requiring changes to the underlying subnet architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple logically separate subnets are used to support different network services, then security and scalability are enhanced, but resource discovery becomes more complex and restricted

Engineering Contradiction:
Improvenetwork securityVSAvoidresource discovery process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network resources discovery proxy is designed as a universal intermediary that can handle discovery requests for multiple different subnets and service types through a single unified interface. It implements a rule-based authorization system that can dynamically determine access permissions across various network segments without requiring separate discovery mechanisms for each subnet, thereby simplifying the overall discovery process while maintaining security boundaries.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If discovery packets are sent directly to each subnet, then the discovery process is simple and direct, but users can access resources in subnets they are not authorized to reach

Engineering Contradiction:
Improvediscovery process simplicityVSAvoidprivacy issues in multi-user environments
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The discovery proxy serves as an intermediary that maintains the simplicity of the discovery process from the user's perspective while adding security enforcement in the background. User devices continue to send discovery requests in the standard manner, but the proxy intercepts these requests, applies authorization rules based on user credentials and subnet policies, and selectively forwards requests to appropriate subnets. This approach preserves ease of operation while preventing unauthorized resource access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11457081B2Network resources discovery system
Publication Date: 2022.09.27 5321 INNOVATION LABS LLC
  • US11457081B2 patent drawing
  • US11457081B2 patent drawing
  • US11457081B2 patent drawing

AI summary

A network resources discovery system regulates the automated discovery of available network resources using a network-enabled device to ensure that the network-enabled device only discovers the specific network resources which it is authorized to access. In use, a network resources discovery proxy includes a local controller which intermediates network resources discovery request and response packets transmitted between the network-enabled device and available network resources. By comparing the network resources discovery packets against a local, modifiable set of matching rules, the network resources discovery proxy is able to filter out the automated discovery of any types of services and devices provided by a computer network which the network-enabled device is not permitted to receive. By restricting the automated discovery of network resources in accordance with the local set of matching rules, the network resources discovery system provides an enhanced level of network security through the selective isolation of network devices.