Network Modeling Scheme for Dynamic User Identity Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End-to-end network modeling technologies face challenges in accurately identifying user identities in dynamic environments, where users may log in from various devices and locations, making it difficult to collect and analyze live data on dynamic users and enforce identity-based policies across complex networks.

Innovation Solution

A network modeling scheme that treats user roles as network locations, distinguishing between dynamic and static rules, and models identity enforcement approaches by representing identity groups as structural objects, allowing for accurate tracking of active endpoints and correct configuration analysis to ensure intended access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If end-to-end network modeling is used to track user identities across dynamic endpoints, then identity-based access control accuracy is improved, but device complexity and difficulty of detecting and measuring increase

Engineering Contradiction:
Improveidentity identification accuracyVSAvoidnetwork modeling complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between dynamic user identities and static network modeling. This intermediary maintains identity mappings and translates dynamic user behaviors into structured data that can be processed by existing network modeling tools, thereby improving identity identification accuracy without directly increasing the complexity of the core network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identity tracking function into separate modular components that can be independently managed and analyzed. By dividing the complex identity management system into discrete segments (identity collection, mapping, enforcement), the overall complexity is reduced while maintaining measurement precision through focused analysis of each segment.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If live data collection on dynamic users is implemented, then identity tracking accuracy is improved, but loss of time and difficulty of detecting and measuring increase

Engineering Contradiction:
Improveuser identity tracking accuracyVSAvoiddata collection and analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing identity mapping frameworks and data collection templates before actual user tracking begins. This allows the system to quickly populate and analyze identity data without requiring extensive real-time processing, thereby reducing the time loss associated with live data collection while maintaining tracking accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If identity enforcement policies are applied across complex networks, then access control reliability is improved, but device complexity and difficulty of operation increase

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses copying by creating simplified virtual representations of identity enforcement policies that can be tested and validated before deployment. These policy copies allow operators to verify access control reliability in a low-risk environment, reducing the operational complexity associated with implementing policies across complex networks while maintaining the reliability of the actual enforcement mechanisms.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9325719B2Method and system for evaluating access granted to users moving dynamically across endpoints in a network
Publication Date: 2016.04.26 REDSEAL INC
  • US9325719B2 patent drawing
  • US9325719B2 patent drawing
  • US9325719B2 patent drawing

AI summary

A network analysis tool is provided in support of a data communication network having user devices at indeterminate endpoints wherein user identities, namely, the collection of meta-data about a user device of a network (beyond the conventional networking concept of an endpoint address), is modeled as fixed endpoints for purposes of tracking. More specifically, users at indeterminate endpoints are identified by modeling using user roles as models of the user devices.