Optical Network Resource Segmentation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In optical networks, shared network resources among multiple users pose security issues and service disruptions due to unauthorized access and operations, as users may inadvertently or maliciously affect resources not exclusively theirs.

Innovation Solution

A network management system that determines and stores user relationships with network resources, allowing only authorized users to view and modify their associated resources, and coordinates operations among users to prevent disruptions by segregating and managing access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network resources are shared among multiple users, then resource utilization efficiency is improved, but network security and access control become more difficult to manage

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments network resource access by creating distinct user-specific views of shared resources. Each user sees only the portion of shared resources they are authorized to access, while the underlying physical sharing remains intact. This segmentation resolves the contradiction by maintaining high resource utilization through sharing while improving security through view isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the network management system with view configuration) that mediates between multiple users and shared resources. This intermediary controls what each user can see and access, allowing resource sharing while enforcing security policies. The intermediary resolves the contradiction by decoupling physical sharing from logical access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users can access shared network resources, then resource availability is improved, but unauthorized operations and service disruptions increase

Engineering Contradiction:
Improveresource availabilityVSAvoidunauthorized operations
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by giving each user a customized view of shared resources with specific access permissions. Instead of uniform access control, each user experiences tailored visibility and operation rights based on their authorization level. This resolves the contradiction by maintaining resource availability for authorized users while preventing unauthorized operations through view-specific permission enforcement.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by pre-configuring user-specific views that inherently prevent unauthorized access. Before users can perform operations, the system has already established what they can and cannot see or modify. This proactive approach resolves the contradiction by ensuring resource availability through pre-approved access while blocking harmful unauthorized operations before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Loss of information

If optical network information is provided to users, then user awareness and control are improved, but information security and privacy risks increase

Engineering Contradiction:
Improveuser awarenessVSAvoidinformation security risks
Core Design Contradiction:
Loss of informationVSObject-generated harmful factors

Solution Approach 1:

The patent segments optical network information into user-specific portions, where each user receives only the information relevant to their authorized resources. This segmentation provides users with necessary awareness and control over their own resources while preventing exposure of other users' sensitive information. The contradiction is resolved by delivering adequate information for user control without creating security risks through information overexposure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9769087B2Providing ownership-based view and management of shared optical network resources
Publication Date: 2017.09.19 INFINERA CORP
  • US9769087B2 patent drawing
  • US9769087B2 patent drawing
  • US9769087B2 patent drawing

AI summary

A device may receive optical network information associated with an optical network, and may determine a user associated with network resources of the optical network. The network resources may be shared for use by multiple users, including the user. The device may store the optical network information and information that identifies a relationship between the user and the network resources. The device may receive a request for at least a portion of the optical network information associated with the user and the network resources. The device may identify the network resources, associated with the user, based on storing the optical network information and the information that identifies the relationship The device may provide the at least the portion of the optical network information, including information associated with the network resources associated with the user, based on identifying the network resources.