Network Traffic Manager Context-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic management solutions, such as firewalls, face high processing power requirements and significant delays when handling large volumes of incoming packets due to dynamic generation of firewall rules through deep packet inspection, making it inefficient for managing access to private networks.

Innovation Solution

A method that uses context parameters to select predefined policies associated with network entitlement rules, allowing for efficient and secure network access by eliminating the need for deep packet inspection, where context parameters include device, user, and system parameters to determine access rights, and static network entitlement rules are applied once policies are selected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to dynamically generate firewall rules, then network access control accuracy is improved, but processing power requirements increase and handling speed decreases

Engineering Contradiction:
Improvenetwork access control accuracyVSAvoidpacket handling speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-defining access policies and entitlement rules before actual packet processing occurs. Instead of dynamically analyzing packet content in real-time, the system pre-establishes the framework for access control decisions, allowing rapid matching during packet handling without deep inspection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the access control process into two distinct phases: policy definition phase (where access policies and entitlement rules are established) and packet processing phase (where pre-defined policies are matched against incoming packets). This segmentation eliminates the need for deep packet inspection during the processing phase, significantly improving handling speed.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If deep packet inspection is used to dynamically generate firewall rules, then network access control accuracy is improved, but processing time increases causing delays

Engineering Contradiction:
Improvenetwork access control accuracyVSAvoidpacket processing delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs all complex access control logic and policy definition in advance during the policy definition phase. During actual packet processing, the system only needs to match incoming packets against pre-defined policies, eliminating time-consuming deep packet inspection and reducing processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By dividing the access control process into policy definition and packet processing segments, the patent ensures that time-consuming analysis occurs only when policies are being defined, not during high-volume packet processing, thus minimizing processing delays.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If dynamic firewall rule generation is implemented, then adaptability to different access scenarios is improved, but device complexity increases

Engineering Contradiction:
Improveaccess scenario adaptabilityVSAvoidfirewall processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall functionality into two independent parts: a policy definition component that handles adaptability and scenario configuration, and a packet processing component that handles simple pattern matching. This segmentation allows the system to maintain adaptability through policy flexibility while reducing processing complexity by eliminating deep inspection requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of pre-defined access policies and entitlement rules that mediates between the complex adaptability requirements and the simple packet processing needs. This intermediary framework allows the system to be adaptable without requiring complex real-time analysis during packet processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10715496B2Client network access provision by a network traffic manager
Publication Date: 2020.07.14 CRYPTZONE NORTH AMERICA
  • US10715496B2 patent drawing
  • US10715496B2 patent drawing
  • US10715496B2 patent drawing

AI summary

In one embodiment, a computer implemented method provides a client computing device network access to a private network by a network traffic manager, and the method includes: obtaining context parameters related to a context of the client computing device; selecting as a function of the context parameters one or more policies as selected policies, wherein each policy is associated with one or more network entitlement rules defining network access rules to a networking device or an application in the private network according to the policy; retrieving the one or more network entitlement rules associated with the selected policies; and providing the network traffic manager with the one or more network entitlement rules, thereby providing the client computing device the network access.