Network Management Interface Security Wrapper

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control mechanisms in network management systems cannot effectively restrict access to management interfaces, allowing unauthorized management systems to access proprietary data models and enabling reverse engineering, as equipment operators have control over access rules and cannot distinguish approved from unapproved management systems.

Innovation Solution

Implementing a security wrapper within the data model using a valid security credential as a key, where the credential is supplied by the equipment provider and inaccessible to the equipment operator, to restrict access to protected parts of the data model, thereby hiding proprietary information while still providing functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing access control mechanisms are used to restrict access to management interface, then access control is implemented, but equipment operators can still control access rules and cannot distinguish approved from unapproved management systems

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidequipment operator control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into two distinct layers: (1) equipment operator control over basic access rules and personnel authentication, and (2) equipment provider control over management system approval through embedded credentials in the data model. This segmentation allows both parties to have appropriate control without interfering with each other's authority.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to access control by embedding approval credentials directly within the data model structure itself. Instead of relying solely on external access control lists or authentication mechanisms, the data model contains intrinsic credentials that enable or disable specific management systems at a deeper architectural level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If management interface is made open and accessible to any management system, then ease of operation is improved, but proprietary data model details can be exposed and reverse engineered

Engineering Contradiction:
Improvemanagement interface accessibilityVSAvoidproprietary data model exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies local quality by making different portions of the data model accessible with different levels of protection. Non-sensitive portions remain openly accessible for ease of operation, while sensitive proprietary portions contain embedded credentials that restrict access to only approved management systems, thus protecting against reverse engineering.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The embedded credentials act as an intermediary mechanism between the open management interface and the proprietary data model. They mediate access by automatically enabling or disabling specific management systems based on credential matching, allowing open accessibility while preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security credentials are embedded in the data model to restrict access, then access security is improved, but device complexity increases

Engineering Contradiction:
Improvemanagement interface securityVSAvoiddata model structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security credential storage with the existing data model structure rather than creating a separate security infrastructure. By combining authentication credentials directly into the data model elements, the system achieves enhanced security without adding separate complex security management systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11757853B2Method for restricting access to a management interface using standard management protocols and software
Publication Date: 2023.09.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11757853B2 patent drawing
  • US11757853B2 patent drawing
  • US11757853B2 patent drawing

AI summary

A method by a network device to restrict access to a management interface, where the management interface is defined by a data model, and where the network device is provided by an equipment provider to an equipment operator for use by the equipment operator. The method includes receiving a first request from a management system to perform a first management operation that involves accessing a module of the data model, where the first request specifies a security credential as a key for a security wrapper defined by the module, and where the security credential is supplied to the management system by the equipment provider and is inaccessible to the equipment operator, verifying whether the security credential specified by the first request is valid, and performing the first management operation in response to verifying that the security credential specified by the first request is valid.