Policy Mediation in Wireless Networks for Zero-Trust Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In zero-trust wireless communication networks, conflicting authorization decisions arise due to independently defined and enforced security policies across multiple security domains, leading to access control challenges when a user device requests access to network resources.
Innovation Solution
A Policy Application Function (PAF) mediates conflicting policy decisions from multiple Policy Decision Points (PDPs) by correlating policies to layers of the OSI protocol stack, selecting appropriate policies, and indicating them to Policy Enforcement Points (PEPs for implementation, ensuring consistent access control across shared security domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security domains independently enforce their own security policies, then each domain can maintain its own security requirements and privileges, but conflicting authorization decisions occur leading to access control challenges
Solution Approach 1:
The patent introduces a Policy Mediation Point (PMP) as an intermediary between multiple Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs). The PMP receives policy decisions from multiple PDPs, mediates conflicts between them, and selects appropriate policies for enforcement. This mediator resolves authorization conflicts without requiring changes to the independent security domains, thus maintaining reliability while improving ease of operation.
Solution Approach 2:
The PMP performs multiple functions: receiving policies from multiple PDPs, correlating policies to OSI layers, selecting appropriate policies, and distributing them to PEPs. This multi-functional component handles diverse security requirements from different domains uniformly, enabling the system to manage complex multi-domain access control through a single universal mechanism.
2Adaptability or versatility
If security policies are independently defined and enforced in a zero-trust environment, then each entity can control access according to its own security requirements, but the system complexity increases due to multiple PDPs and policy conflicts
Solution Approach 1:
The patent segments the policy management function into distinct components: multiple independent PDPs that define domain-specific policies, a central PMP that mediates and selects policies, and PEPs that enforce policies. This segmentation allows each PDP to maintain policy customization independence while the PMP handles the complexity of policy integration and conflict resolution, reducing overall system complexity.
Solution Approach 2:
The PMP acts as an intermediary that simplifies the complex interactions between multiple PDPs and PEPs. It provides a standardized interface for policy submission, correlation, and selection, thereby reducing the complexity of direct multi-to-many interactions while preserving the adaptability of independent policy definition.
3Reliability
If multiple PDPs evaluate access requests according to their own security policies, then each domain can enforce its specific authorization rules, but conflicting authorization decisions arise that prevent consistent access control
Solution Approach 1:
The PMP mediates between multiple PDPs to ensure consistent authorization decisions. It receives policy decisions from multiple PDPs, correlates them to appropriate OSI layers, and selects policies that satisfy all affected security domains. This mediation process maintains domain-specific security enforcement while ensuring stable and consistent authorization outcomes.
Solution Approach 2:
The patent changes the parameter of policy selection by introducing layer correlation. The PMP correlates policies to specific OSI layers and selects policies based on layer-appropriate criteria. This parameter change enables the system to handle conflicting decisions by applying different selection strategies at different protocol layers, thereby maintaining both domain-specific enforcement and decision consistency.
4Adaptability or versatility
If a shared PEP is controlled by multiple PDPs of different security domains, then the PEP can enforce policies from multiple domains, but the PEP receives conflicting policy instructions that complicate policy implementation
Solution Approach 1:
The patent extracts the policy selection function from the PEP and places it in the PMP. The PEP's role is simplified to only enforcing policies received from the PMP, while the PMP handles the complex task of receiving, correlating, and selecting policies from multiple PDPs. This extraction reduces the complexity at the PEP while maintaining multi-domain enforcement capability.
Solution Approach 2:
The PMP serves as an intermediary between multiple PDPs and the shared PEP. It consolidates conflicting policy instructions from multiple PDPs, resolves conflicts through correlation and selection, and provides a single set of resolved policies to the PEP. This mediation simplifies policy management at the PEP while preserving the ability to enforce multiple domain policies.
Data Source
AI summary
Technology including systems, methods, and devices is disclosed herein to operate a wireless communication system to serve a wireless communication device based on policies. In an implementation, a method of operating a wireless communication system includes receiving policies for a wireless device from multiple policy sources. The method includes correlating policies to layers of a protocol and selecting ones of the policies for ones of the layers based on the correlations. The method further includes indicating the selected ones of the policies to one or more enforcement points.


