Flexible Network Access Control via RADIUS Vendor Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions lack flexibility in defining access control policies, particularly due to the inability to utilize vendor-specific attributes, leading to inadequate visibility and control in managing network access across physical and virtual infrastructures.

Innovation Solution

A system and method that capture session attributes and external attributes, derive response attributes based on access control policy rules, and apply them to sessions, enabling flexible network access control policies by incorporating RADIUS vendor-specific attributes, health levels, device groups, user groups, and time of day, among others, to authorize access and enforce security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network security solutions are used, then basic access control is provided, but flexibility in defining access control policies is limited

Engineering Contradiction:
Improveflexibility in defining access control policiesVSAvoidcomplexity of policy definition
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically adapts access control policies based on real-time session attributes and external attributes. The policy evaluation engine continuously assesses current session state and external factors to determine appropriate access decisions, allowing policies to be flexible and adaptive rather than static and rigid.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes policy parameters based on attribute values. By capturing session attributes (source/destination IP, port, protocol) and external attributes (user profile, device information, threat intelligence), the system dynamically adjusts access control parameters to match current conditions, enabling flexible policy definition without increased complexity.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If vendor-specific attributes are not utilized, then system simplicity is maintained, but visibility and control in managing network access is inadequate

Engineering Contradiction:
Improvevisibility in managing network accessVSAvoidattribute processing capability
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The attribute capture module is designed to handle multiple attribute types universally - both standard RADIUS attributes and vendor-specific attributes. This multi-functional capability allows the system to process diverse attribute formats through a unified framework, improving visibility without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary attribute processing layer between the network infrastructure and policy enforcement points. This intermediary captures and standardizes various attribute formats (including vendor-specific ones) into a unified structure that can be easily evaluated by policy rules, enhancing visibility while maintaining manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive session attributes are captured, then access control precision is improved, but processing overhead increases

Engineering Contradiction:
Improveprecision of access control decisionsVSAvoidprocessing time for attribute capture and evaluation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary attribute capture and validation during session establishment. By collecting session attributes (source IP, destination IP, port, protocol) and external attributes (user profile, device info) upfront, the system prepares evaluation data before policy decisions are required, reducing real-time processing overhead while maintaining high precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the most relevant attributes needed for policy evaluation from the comprehensive set of available attributes. The policy definition language allows selective use of attributes based on specific policy requirements, capturing precision without processing unnecessary data that would increase overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9210193B2System and method for flexible network access control policies in a network environment
Publication Date: 2015.12.08 MCAFEE LLC
  • US9210193B2 patent drawing
  • US9210193B2 patent drawing
  • US9210193B2 patent drawing

AI summary

An example method includes capturing session attributes associated with a communication session initiated by a node in a network environment, querying external attributes associated with the node, deriving a response attribute according to an access control policy rule based on at least one of the session attributes and at least one of the external attributes, and applying the response attribute to the communication session. The session attributes can include remote authentication dial in user service RADIUS vendor specific attribute information from an unknown vendor. The method may further include auditing the communication session, enforcing the response attribute, or ignoring the access control policy. Enforcing the response attribute can include taking an access control action according to the response attribute. The access control action may include allowing the node to access a virtual local area network in the network environment, denying access to the network environment, etc.