Network Management Interface Security Wrapper
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control mechanisms in network management systems cannot effectively restrict access to management interfaces, allowing unauthorized management systems to access proprietary data models and enabling reverse engineering, as equipment operators have control over access rules and cannot distinguish approved from unapproved management systems.
Innovation Solution
Implementing a security wrapper within the data model using a valid security credential as a key, where the credential is supplied by the equipment provider and inaccessible to the equipment operator, to restrict access to protected parts of the data model, thereby hiding proprietary information while still providing functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing access control mechanisms are used to restrict access to management interface, then access control is implemented, but equipment operators can still control access rules and cannot distinguish approved from unapproved management systems
Solution Approach 1:
The patent segments access control into two distinct layers: (1) equipment operator control over basic access rules and personnel authentication, and (2) equipment provider control over management system approval through embedded credentials in the data model. This segmentation allows both parties to have appropriate control without interfering with each other's authority.
Solution Approach 2:
The patent adds a new dimension to access control by embedding approval credentials directly within the data model structure itself. Instead of relying solely on external access control lists or authentication mechanisms, the data model contains intrinsic credentials that enable or disable specific management systems at a deeper architectural level.
2Ease of operation
If management interface is made open and accessible to any management system, then ease of operation is improved, but proprietary data model details can be exposed and reverse engineered
Solution Approach 1:
The patent applies local quality by making different portions of the data model accessible with different levels of protection. Non-sensitive portions remain openly accessible for ease of operation, while sensitive proprietary portions contain embedded credentials that restrict access to only approved management systems, thus protecting against reverse engineering.
Solution Approach 2:
The embedded credentials act as an intermediary mechanism between the open management interface and the proprietary data model. They mediate access by automatically enabling or disabling specific management systems based on credential matching, allowing open accessibility while preventing unauthorized access to sensitive information.
3Reliability
If security credentials are embedded in the data model to restrict access, then access security is improved, but device complexity increases
Solution Approach 1:
The patent merges the security credential storage with the existing data model structure rather than creating a separate security infrastructure. By combining authentication credentials directly into the data model elements, the system achieves enhanced security without adding separate complex security management systems.
Data Source
AI summary
A method by a network device to restrict access to a management interface, where the management interface is defined by a data model, and where the network device is provided by an equipment provider to an equipment operator for use by the equipment operator. The method includes receiving a first request from a management system to perform a first management operation that involves accessing a module of the data model, where the first request specifies a security credential as a key for a security wrapper defined by the module, and where the security credential is supplied to the management system by the equipment provider and is inaccessible to the equipment operator, verifying whether the security credential specified by the first request is valid, and performing the first management operation in response to verifying that the security credential specified by the first request is valid.


