Flexible Network Access Control via RADIUS Vendor Attributes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions lack flexibility in defining access control policies, particularly due to the inability to utilize vendor-specific attributes, leading to inadequate visibility and control in managing network access across physical and virtual infrastructures.
Innovation Solution
A system and method that capture session attributes and external attributes, derive response attributes based on access control policy rules, and apply them to sessions, enabling flexible network access control policies by incorporating RADIUS vendor-specific attributes, health levels, device groups, user groups, and time of day, among others, to authorize access and enforce security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network security solutions are used, then basic access control is provided, but flexibility in defining access control policies is limited
Solution Approach 1:
The system dynamically adapts access control policies based on real-time session attributes and external attributes. The policy evaluation engine continuously assesses current session state and external factors to determine appropriate access decisions, allowing policies to be flexible and adaptive rather than static and rigid.
Solution Approach 2:
The system changes policy parameters based on attribute values. By capturing session attributes (source/destination IP, port, protocol) and external attributes (user profile, device information, threat intelligence), the system dynamically adjusts access control parameters to match current conditions, enabling flexible policy definition without increased complexity.
2Loss of information
If vendor-specific attributes are not utilized, then system simplicity is maintained, but visibility and control in managing network access is inadequate
Solution Approach 1:
The attribute capture module is designed to handle multiple attribute types universally - both standard RADIUS attributes and vendor-specific attributes. This multi-functional capability allows the system to process diverse attribute formats through a unified framework, improving visibility without proportionally increasing complexity.
Solution Approach 2:
The system introduces an intermediary attribute processing layer between the network infrastructure and policy enforcement points. This intermediary captures and standardizes various attribute formats (including vendor-specific ones) into a unified structure that can be easily evaluated by policy rules, enhancing visibility while maintaining manageable complexity.
3Measurement precision
If comprehensive session attributes are captured, then access control precision is improved, but processing overhead increases
Solution Approach 1:
The system performs preliminary attribute capture and validation during session establishment. By collecting session attributes (source IP, destination IP, port, protocol) and external attributes (user profile, device info) upfront, the system prepares evaluation data before policy decisions are required, reducing real-time processing overhead while maintaining high precision.
Solution Approach 2:
The system extracts only the most relevant attributes needed for policy evaluation from the comprehensive set of available attributes. The policy definition language allows selective use of attributes based on specific policy requirements, capturing precision without processing unnecessary data that would increase overhead.
Data Source
AI summary
An example method includes capturing session attributes associated with a communication session initiated by a node in a network environment, querying external attributes associated with the node, deriving a response attribute according to an access control policy rule based on at least one of the session attributes and at least one of the external attributes, and applying the response attribute to the communication session. The session attributes can include remote authentication dial in user service RADIUS vendor specific attribute information from an unknown vendor. The method may further include auditing the communication session, enforcing the response attribute, or ignoring the access control policy. Enforcing the response attribute can include taking an access control action according to the response attribute. The access control action may include allowing the node to access a virtual local area network in the network environment, denying access to the network environment, etc.


