Network Modeling Scheme for Dynamic User Identity Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
End-to-end network modeling technologies face challenges in accurately identifying user identities in dynamic environments, where users may log in from various devices and locations, making it difficult to collect and analyze live data on dynamic users and enforce identity-based policies across complex networks.
Innovation Solution
A network modeling scheme that treats user roles as network locations, distinguishing between dynamic and static rules, and models identity enforcement approaches by representing identity groups as structural objects, allowing for accurate tracking of active endpoints and correct configuration analysis to ensure intended access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If end-to-end network modeling is used to track user identities across dynamic endpoints, then identity-based access control accuracy is improved, but device complexity and difficulty of detecting and measuring increase
Solution Approach 1:
The patent introduces an intermediary component that acts as a bridge between dynamic user identities and static network modeling. This intermediary maintains identity mappings and translates dynamic user behaviors into structured data that can be processed by existing network modeling tools, thereby improving identity identification accuracy without directly increasing the complexity of the core network infrastructure.
Solution Approach 2:
The patent segments the identity tracking function into separate modular components that can be independently managed and analyzed. By dividing the complex identity management system into discrete segments (identity collection, mapping, enforcement), the overall complexity is reduced while maintaining measurement precision through focused analysis of each segment.
2Measurement precision
If live data collection on dynamic users is implemented, then identity tracking accuracy is improved, but loss of time and difficulty of detecting and measuring increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing identity mapping frameworks and data collection templates before actual user tracking begins. This allows the system to quickly populate and analyze identity data without requiring extensive real-time processing, thereby reducing the time loss associated with live data collection while maintaining tracking accuracy.
3Reliability
If identity enforcement policies are applied across complex networks, then access control reliability is improved, but device complexity and difficulty of operation increase
Solution Approach 1:
The patent uses copying by creating simplified virtual representations of identity enforcement policies that can be tested and validated before deployment. These policy copies allow operators to verify access control reliability in a low-risk environment, reducing the operational complexity associated with implementing policies across complex networks while maintaining the reliability of the actual enforcement mechanisms.
Data Source
AI summary
A network analysis tool is provided in support of a data communication network having user devices at indeterminate endpoints wherein user identities, namely, the collection of meta-data about a user device of a network (beyond the conventional networking concept of an endpoint address), is modeled as fixed endpoints for purposes of tracking. More specifically, users at indeterminate endpoints are identified by modeling using user roles as models of the user devices.


