Network Policy Enforcement via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users with direct access to network elements can circumvent policies implemented by network management systems, allowing unauthorized execution of configuration commands, which undermines network security and management control.

Innovation Solution

A network management system with a policy management module that enables administrators to define and enforce policies across users, roles, and network elements, ensuring that only authorized commands can be executed on network elements, and providing a web portal for centralized management and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are granted direct access to network elements for configuration commands, then operational flexibility and speed are improved, but security control and policy enforcement deteriorate

Engineering Contradiction:
Improveoperational flexibilityVSAvoidpolicy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a policy management system as an intermediary layer between users and network elements. This mediator intercepts configuration commands, evaluates them against defined policies, and selectively permits or denies execution. The system maintains operational flexibility by allowing authorized commands while ensuring policy compliance through the intermediary policy enforcement mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct user access to network elements is allowed, then command execution speed is improved, but unauthorized access and security risks increase

Engineering Contradiction:
Improvecommand execution speedVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-defining policies and permissions before users attempt to execute commands. The system预先 establishes what commands are authorized for each user and under what conditions. When a command is issued, the pre-configured policies are immediately applied, enabling fast authorization decisions without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized policy management is implemented, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a policy management system that handles multiple functions through a single integrated platform. The system can manage user authentication, command authorization, policy definition, and monitoring all through one centralized interface. This multi-functional approach consolidates what could be multiple separate systems into a unified solution, reducing overall system complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8869233B2Policy management within a network management system
Publication Date: 2014.10.21 ATLASSIAN US INC
  • US8869233B2 patent drawing
  • US8869233B2 patent drawing
  • US8869233B2 patent drawing

AI summary

Preferred embodiments of the invention provide systems and methods to maintain a policy within a network management system, receive a command to be executed on one of the one or more network elements, determine whether the command can be executed on the one of the one or more network elements based on the policy maintained within the network management system, and provide an indication that the command can be executed on the one of the one or more network elements based on a determination that the command can be executed on the one of the one or more network elements.