Resource Identifier Access Control for Enterprise Network Alarms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SSL VPN gateways face difficulties in handling alarms from multi-vendor products within an enterprise network, as they are not configured to deliver alarms to external service providers outside the firewall, and authenticating large numbers of service provider technicians is impractical and costly.

Innovation Solution

A resource identifier-based access control approach that activates entries in an authentication database upon alarm generation, providing a dynamic URL or resource identifier to external service providers, allowing them to access the product without the need for a secure gateway or alarm access controller within the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional SSL VPN gateways are used to control access to internal resources, then security is maintained through firewall protection, but external service providers cannot access alarm-generating products and authentication of multiple technicians is impractical

Engineering Contradiction:
Improveaccess control for service providersVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system pre-configures authentication database entries for service provider technicians before they need access. When an alarm occurs, the appropriate entry is already prepared and can be activated immediately, eliminating the need for real-time authentication setup and allowing technicians to access products quickly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication database serves as an intermediary between the firewall-protected internal network and external service providers. It manages credentials and access rights without requiring service providers to directly penetrate the firewall or complex authentication systems, simplifying the access control mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service provider technicians are authenticated individually through conventional methods, then security is maintained, but the administrative burden and cost increase significantly

Engineering Contradiction:
Improveaccess securityVSAvoidadministrative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication database entries are designed to be universal, serving multiple technicians from the same service provider who may need to access different alarm-generating products. A single entry configuration can authenticate multiple technicians, reducing repetitive administrative work while maintaining individual accountability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of creating unique authentication credentials for each technician-product combination, the system creates template entries that can be copied and activated as needed. When a technician needs access, a copy of the appropriate entry is activated rather than creating a new authentication mechanism from scratch.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If no secure gateway is deployed, then implementation costs are reduced, but external service providers need a method to access internal products securely

Engineering Contradiction:
Improveimplementation costVSAvoidsecure access mechanism
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent extracts the authentication functionality from the traditional secure gateway architecture and places it directly in the authentication database. This eliminates the need for a separate secure gateway infrastructure while maintaining secure access capabilities, reducing implementation costs without sacrificing security or ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8218435B2Resource identifier based access control in an enterprise network
Publication Date: 2012.07.10 PULSELINK SYSTEMS LLC
  • US8218435B2 patent drawing
  • US8218435B2 patent drawing
  • US8218435B2 patent drawing

AI summary

An entry in an authentication database of an enterprise network is activated responsive to generation of an alarm by a corresponding product that is part of a set of internal resources of the enterprise network. A dynamic URL or other resource identifier based on the activated entry is supplied to an external service provider associated with the product. The external service provider is granted access to the product responsive to submission of the resource identifier by the service provider.