Network Traffic Manager Context-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic management solutions, such as firewalls, face high processing power requirements and significant delays when handling large volumes of incoming packets due to dynamic generation of firewall rules through deep packet inspection, making it inefficient for managing access to private networks.
Innovation Solution
A method that uses context parameters to select predefined policies associated with network entitlement rules, allowing for efficient and secure network access by eliminating the need for deep packet inspection, where context parameters include device, user, and system parameters to determine access rights, and static network entitlement rules are applied once policies are selected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to dynamically generate firewall rules, then network access control accuracy is improved, but processing power requirements increase and handling speed decreases
Solution Approach 1:
The patent applies preliminary action by pre-defining access policies and entitlement rules before actual packet processing occurs. Instead of dynamically analyzing packet content in real-time, the system pre-establishes the framework for access control decisions, allowing rapid matching during packet handling without deep inspection.
Solution Approach 2:
The patent segments the access control process into two distinct phases: policy definition phase (where access policies and entitlement rules are established) and packet processing phase (where pre-defined policies are matched against incoming packets). This segmentation eliminates the need for deep packet inspection during the processing phase, significantly improving handling speed.
2Measurement precision
If deep packet inspection is used to dynamically generate firewall rules, then network access control accuracy is improved, but processing time increases causing delays
Solution Approach 1:
The system performs all complex access control logic and policy definition in advance during the policy definition phase. During actual packet processing, the system only needs to match incoming packets against pre-defined policies, eliminating time-consuming deep packet inspection and reducing processing delays.
Solution Approach 2:
By dividing the access control process into policy definition and packet processing segments, the patent ensures that time-consuming analysis occurs only when policies are being defined, not during high-volume packet processing, thus minimizing processing delays.
3Adaptability or versatility
If dynamic firewall rule generation is implemented, then adaptability to different access scenarios is improved, but device complexity increases
Solution Approach 1:
The patent segments the firewall functionality into two independent parts: a policy definition component that handles adaptability and scenario configuration, and a packet processing component that handles simple pattern matching. This segmentation allows the system to maintain adaptability through policy flexibility while reducing processing complexity by eliminating deep inspection requirements.
Solution Approach 2:
The patent introduces an intermediary layer of pre-defined access policies and entitlement rules that mediates between the complex adaptability requirements and the simple packet processing needs. This intermediary framework allows the system to be adaptable without requiring complex real-time analysis during packet processing.
Data Source
AI summary
In one embodiment, a computer implemented method provides a client computing device network access to a private network by a network traffic manager, and the method includes: obtaining context parameters related to a context of the client computing device; selecting as a function of the context parameters one or more policies as selected policies, wherein each policy is associated with one or more network entitlement rules defining network access rules to a networking device or an application in the private network according to the policy; retrieving the one or more network entitlement rules associated with the selected policies; and providing the network traffic manager with the one or more network entitlement rules, thereby providing the client computing device the network access.


