Policy Group Access Control for Network Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing access to network resources has increased due to the proliferation of communications and data networks, making it difficult to efficiently control and protect resources with conventional systems, which often require multiple components like access gateways, firewalls, and authentication, authorization, and auditing (AAA) servers.

Innovation Solution

The implementation of policy groups that aggregate access configurations to control user access to network resources, allowing for logical management of access configurations based on logon points, authentication methods, authorization rights, device profiles, and group names, enabling granular access control decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network components (access gateways, firewalls, AAA servers) are used to control access to network resources, then security and access control capability are improved, but system complexity and difficulty of administration increase

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple access control functions (authentication, authorization, resource management) into a unified policy group framework. Policy groups aggregate multiple access configurations and evaluate them collectively to make access decisions, reducing the need for separate components while maintaining comprehensive security control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The policy group mechanism serves multiple functions simultaneously: it performs authentication, authorization, resource allocation, and access decision-making within a single framework. This multi-functional approach replaces the need for separate specialized components, simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple network components and access control mechanisms are deployed, then access security is improved, but ease of operation and management deteriorate

Engineering Contradiction:
Improveaccess securityVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple access configurations into unified policy groups that can be managed as single entities. Administrators can create, modify, and evaluate policy groups collectively rather than managing individual access rules separately, significantly improving management efficiency while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary evaluation of policy groups and access configurations before actual access decisions are made. By pre-configuring and evaluating policy groups with multiple access configurations, the system prepares access control rules in advance, reducing the complexity of real-time access management.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If granular access control decisions are implemented based on multiple factors (authentication, authorization, device profiles), then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into distinct policy groups, each handling specific access configurations. This segmentation allows granular control over different aspects of access (authentication, authorization, device profiles) while organizing them into manageable units that can be evaluated independently and combined systematically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a new dimension of organization by grouping access configurations into policy groups that can be evaluated collectively. This dimensional change transforms the complexity from managing individual granular rules to managing structured groups of rules, making the system more tractable while maintaining precision.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2596609B1System and method for providing a policy group for access control
Publication Date: 2016.09.28 CITRIX SYSTEMS INC
  • EP2596609B1 patent drawingFigure 1A
  • EP2596609B1 patent drawingFigure 1B
  • EP2596609B1 patent drawingFigure 1C

AI summary

The present disclosure is directed towards systems and methods for establishing and applying a policy group (677) to control a user's access to an identified resource. A policy group representing an aggregate of one or more access configurations for a user to access one or more identified resources may be established via a policy manager. The policy group may include a login point component (678) representing an entry point to access the identified resource. The login point may be configured via the policy manager to specify a uniform resource locator for the entry point (666). One or more authentication and authorization methods may be selected for the login point component (699), (690). The device may receive a request to access the uniform resource locator. The device may initiate the policy group for evaluation. The device may initiate, with the user, one or more authentication and authorization methods specified by the login point component.