Role-Based Access Control List Consolidation via Source Role Tags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control methods based on IP addresses require frequent configuration and management of numerous Access Control Lists (ACLs), leading to high workload due to changes in IP addresses, and often necessitate significant modifications to network hardware, which can be costly.
Innovation Solution
Implementing a role-based access control method that uses source and destination role tags, allowing for the combination of multiple ACLs into a single Role-Based Access Control List (RBACL) based on role information, reducing the number of ACLs and minimizing changes to network hardware by utilizing existing QinQ functions in network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented based on IP addresses, then network security can be guaranteed, but the configuration and management workload becomes high due to frequent IP address changes requiring updates to multiple ACLs
Solution Approach 1:
The patent merges multiple IP-based ACLs into a single Role-Based Access Control List (RBACL) that uses role tags instead of IP addresses. This consolidation reduces the number of ACLs from multiple to one, eliminating the need to update multiple configurations when IP addresses change, while maintaining security through role-based verification
Solution Approach 2:
The patent changes the parameter used for access control from IP addresses to role tags. Role tags are assigned to users based on their roles rather than their network addresses, so when IP addresses change, the role tags remain valid and the RBACL does not need to be updated, reducing management workload while maintaining security
2Reliability
If traditional access control methods are used, then security can be maintained, but significant modifications to network hardware are required which increases costs
Solution Approach 1:
The patent makes existing network devices universal by enabling them to perform both traditional packet forwarding and role-based access control functions. The RBACL is implemented in the software plane of existing devices, allowing them to handle multiple functions without requiring dedicated hardware modifications, thus reducing costs while maintaining security
Solution Approach 2:
The patent replaces hardware-based access control mechanisms with software-based role-based access control. Instead of modifying network hardware physically, the solution uses software processing in the control plane to implement RBACL, substituting mechanical hardware changes with software-based solutions that achieve the same security functions at lower cost
3Adaptability or versatility
If multiple ACLs are configured for different IP addresses, then access control can be implemented, but the number of ACLs increases leading to higher management complexity
Solution Approach 1:
The patent combines multiple separate ACLs into a single RBACL that handles access control for multiple roles. Instead of maintaining separate ACLs for different IP addresses or roles, the system uses one unified RBACL that processes role tags, reducing the number of ACLs from multiple to one while preserving access control versatility
Data Source
AI summary
A method and device for processing source role information in which a source role tag is inserted into a packet as an inner VLAN tag of the packet and used to perform role based access control processing for the packet.


