Network Policy Enforcement via Intermediary Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users with direct access to network elements can circumvent policies implemented by network management systems, allowing unauthorized execution of configuration commands, which undermines network security and management control.
Innovation Solution
A network management system with a policy management module that enables administrators to define and enforce policies across users, roles, and network elements, ensuring that only authorized commands can be executed on network elements, and providing a web portal for centralized management and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are granted direct access to network elements for configuration commands, then operational flexibility and speed are improved, but security control and policy enforcement deteriorate
Solution Approach 1:
The patent introduces a policy management system as an intermediary layer between users and network elements. This mediator intercepts configuration commands, evaluates them against defined policies, and selectively permits or denies execution. The system maintains operational flexibility by allowing authorized commands while ensuring policy compliance through the intermediary policy enforcement mechanism.
2Productivity
If direct user access to network elements is allowed, then command execution speed is improved, but unauthorized access and security risks increase
Solution Approach 1:
The patent implements preliminary action by pre-defining policies and permissions before users attempt to execute commands. The system预先 establishes what commands are authorized for each user and under what conditions. When a command is issued, the pre-configured policies are immediately applied, enabling fast authorization decisions without compromising security.
3Reliability
If centralized policy management is implemented, then security control is improved, but system complexity increases
Solution Approach 1:
The patent applies universality by designing a policy management system that handles multiple functions through a single integrated platform. The system can manage user authentication, command authorization, policy definition, and monitoring all through one centralized interface. This multi-functional approach consolidates what could be multiple separate systems into a unified solution, reducing overall system complexity while maintaining comprehensive security control.
Data Source
AI summary
Preferred embodiments of the invention provide systems and methods to maintain a policy within a network management system, receive a command to be executed on one of the one or more network elements, determine whether the command can be executed on the one of the one or more network elements based on the policy maintained within the network management system, and provide an indication that the command can be executed on the one of the one or more network elements based on a determination that the command can be executed on the one of the one or more network elements.


