Policy Mediation in Wireless Networks for Zero-Trust Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In zero-trust wireless communication networks, conflicting authorization decisions arise due to independently defined and enforced security policies across multiple security domains, leading to access control challenges when a user device requests access to network resources.

Innovation Solution

A Policy Application Function (PAF) mediates conflicting policy decisions from multiple Policy Decision Points (PDPs) by correlating policies to layers of the OSI protocol stack, selecting appropriate policies, and indicating them to Policy Enforcement Points (PEPs for implementation, ensuring consistent access control across shared security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security domains independently enforce their own security policies, then each domain can maintain its own security requirements and privileges, but conflicting authorization decisions occur leading to access control challenges

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a Policy Mediation Point (PMP) as an intermediary between multiple Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs). The PMP receives policy decisions from multiple PDPs, mediates conflicts between them, and selects appropriate policies for enforcement. This mediator resolves authorization conflicts without requiring changes to the independent security domains, thus maintaining reliability while improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The PMP performs multiple functions: receiving policies from multiple PDPs, correlating policies to OSI layers, selecting appropriate policies, and distributing them to PEPs. This multi-functional component handles diverse security requirements from different domains uniformly, enabling the system to manage complex multi-domain access control through a single universal mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If security policies are independently defined and enforced in a zero-trust environment, then each entity can control access according to its own security requirements, but the system complexity increases due to multiple PDPs and policy conflicts

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidpolicy framework structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management function into distinct components: multiple independent PDPs that define domain-specific policies, a central PMP that mediates and selects policies, and PEPs that enforce policies. This segmentation allows each PDP to maintain policy customization independence while the PMP handles the complexity of policy integration and conflict resolution, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The PMP acts as an intermediary that simplifies the complex interactions between multiple PDPs and PEPs. It provides a standardized interface for policy submission, correlation, and selection, thereby reducing the complexity of direct multi-to-many interactions while preserving the adaptability of independent policy definition.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple PDPs evaluate access requests according to their own security policies, then each domain can enforce its specific authorization rules, but conflicting authorization decisions arise that prevent consistent access control

Engineering Contradiction:
Improvedomain-specific security enforcementVSAvoidauthorization decision consistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The PMP mediates between multiple PDPs to ensure consistent authorization decisions. It receives policy decisions from multiple PDPs, correlates them to appropriate OSI layers, and selects policies that satisfy all affected security domains. This mediation process maintains domain-specific security enforcement while ensuring stable and consistent authorization outcomes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of policy selection by introducing layer correlation. The PMP correlates policies to specific OSI layers and selects policies based on layer-appropriate criteria. This parameter change enables the system to handle conflicting decisions by applying different selection strategies at different protocol layers, thereby maintaining both domain-specific enforcement and decision consistency.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If a shared PEP is controlled by multiple PDPs of different security domains, then the PEP can enforce policies from multiple domains, but the PEP receives conflicting policy instructions that complicate policy implementation

Engineering Contradiction:
Improvemulti-domain policy enforcementVSAvoidpolicy management at PEP
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the policy selection function from the PEP and places it in the PMP. The PEP's role is simplified to only enforcing policies received from the PMP, while the PMP handles the complex task of receiving, correlating, and selecting policies from multiple PDPs. This extraction reduces the complexity at the PEP while maintaining multi-domain enforcement capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The PMP serves as an intermediary between multiple PDPs and the shared PEP. It consolidates conflicting policy instructions from multiple PDPs, resolves conflicts through correlation and selection, and provides a single set of resolved policies to the PEP. This mediation simplifies policy management at the PEP while preserving the ability to enforce multiple domain policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240236678A1Policy mediation and delivery to enforcement points in wireless communication networks
Publication Date: 2024.07.11 T MOBILE INNOVATIONS LLC
  • US20240236678A1 patent drawing
  • US20240236678A1 patent drawing
  • US20240236678A1 patent drawing

AI summary

Technology including systems, methods, and devices is disclosed herein to operate a wireless communication system to serve a wireless communication device based on policies. In an implementation, a method of operating a wireless communication system includes receiving policies for a wireless device from multiple policy sources. The method includes correlating policies to layers of a protocol and selecting ones of the policies for ones of the layers based on the correlations. The method further includes indicating the selected ones of the policies to one or more enforcement points.