Overlay Network Connection Revocation via Privilege Mismatch Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed network environments, managing and monitoring infrastructure access becomes challenging due to changes in access privileges, making it difficult to rapidly identify users or resources affected by these changes, especially across remote offices and jurisdictions with varying regulatory requirements.

Innovation Solution

The implementation of a system that determines sessions associated with secure tunnels, compares privilege information of users with resource requirements, and sends revoke messages to agents to close connections when mismatches are found, utilizing mesh agents and infrastructure security computers to manage and revoke access in overlay networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed network environments are used to enable remote services and cross-jurisdictional access, then network versatility and service availability are improved, but monitoring and managing infrastructure access becomes more difficult and time-consuming

Engineering Contradiction:
Improvenetwork versatilityVSAvoidtime to monitor and manage access
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system continuously monitors access privileges and automatically detects changes in user credentials or resource requirements. When a mismatch is detected, the system provides feedback by sending revoke messages to agents, enabling automatic correction without manual intervention. This continuous monitoring and automatic response mechanism resolves the contradiction by maintaining network versatility while eliminating the time-consuming manual monitoring burden.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access management system performs self-service by automatically detecting privilege mismatches and revoking inappropriate access rights without requiring manual administrative intervention. The system monitors its own state, identifies anomalies, and executes corrective actions autonomously, thereby maintaining network versatility while eliminating time losses associated with manual access management.

Inventive Principle:
Principle #25Self-service

2Device complexity

If manual methods are used to identify users affected by access privilege changes, then system complexity is reduced, but the speed and efficiency of connection revocation deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidconnection revocation speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system performs preliminary actions by establishing agents on network resources beforehand and pre-configuring the monitoring infrastructure. These agents continuously track access privileges and resource requirements, so when changes occur, the system can immediately identify affected users and execute revocation without delay. This preliminary setup increases productivity while maintaining manageable system complexity through standardized agent deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces intermediary agents that act as mediators between users and network resources. These agents continuously report access status and privilege changes to the central system, enabling rapid identification of affected users when privilege mismatches occur. The intermediary layer automates the detection and notification process, dramatically increasing connection revocation speed without significantly increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If continuous monitoring of access privileges is implemented, then network security is improved, but system resource consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic monitoring through agents that check access privileges at scheduled intervals rather than continuously. The monitoring frequency is adjusted based on risk levels and change patterns, performing comprehensive checks when changes are detected and reducing intensity during stable periods. This periodic approach maintains network security reliability while significantly reducing system resource consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial monitoring intensity by focusing resources on detecting changes rather than continuously verifying all access privileges. When privilege changes or anomalies are detected, the system intensifies monitoring to ensure rapid detection and revocation. During stable periods, monitoring is reduced to essential checks, maintaining security reliability while optimizing resource consumption through variable monitoring intensity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11973752B2Connection revocation in overlay networks
Publication Date: 2024.04.30 DELINEA INC
  • US11973752B2 patent drawing
  • US11973752B2 patent drawing
  • US11973752B2 patent drawing

AI summary

Embodiments are directed to connection revocation in overlay networks. An overlay network may be employed to provide secure tunnels between clients and resources. In response to a privilege evaluation event, performing further actions, including: determining sessions associated with the secure tunnels; determining users and a portion of the resources based on the sessions such that each determined user and each determined resource are associated with a same session; comparing privilege information associated with each determined user with privilege requirements associated with each determined resource. In response to determining one or more mismatches of the privilege information and the privilege requirements based on the comparison, performing further actions, including: determining revocable sessions based on the mismatches; providing revoke messages to agents such that the agents close connections associated with the revocable sessions.