Role-Based Access Control List Consolidation via Source Role Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control methods based on IP addresses require frequent configuration and management of numerous Access Control Lists (ACLs), leading to high workload due to changes in IP addresses, and often necessitate significant modifications to network hardware, which can be costly.

Innovation Solution

Implementing a role-based access control method that uses source and destination role tags, allowing for the combination of multiple ACLs into a single Role-Based Access Control List (RBACL) based on role information, reducing the number of ACLs and minimizing changes to network hardware by utilizing existing QinQ functions in network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented based on IP addresses, then network security can be guaranteed, but the configuration and management workload becomes high due to frequent IP address changes requiring updates to multiple ACLs

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration and management workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple IP-based ACLs into a single Role-Based Access Control List (RBACL) that uses role tags instead of IP addresses. This consolidation reduces the number of ACLs from multiple to one, eliminating the need to update multiple configurations when IP addresses change, while maintaining security through role-based verification

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameter used for access control from IP addresses to role tags. Role tags are assigned to users based on their roles rather than their network addresses, so when IP addresses change, the role tags remain valid and the RBACL does not need to be updated, reducing management workload while maintaining security

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional access control methods are used, then security can be maintained, but significant modifications to network hardware are required which increases costs

Engineering Contradiction:
ImprovesecurityVSAvoidhardware modification costs
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent makes existing network devices universal by enabling them to perform both traditional packet forwarding and role-based access control functions. The RBACL is implemented in the software plane of existing devices, allowing them to handle multiple functions without requiring dedicated hardware modifications, thus reducing costs while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces hardware-based access control mechanisms with software-based role-based access control. Instead of modifying network hardware physically, the solution uses software processing in the control plane to implement RBACL, substituting mechanical hardware changes with software-based solutions that achieve the same security functions at lower cost

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If multiple ACLs are configured for different IP addresses, then access control can be implemented, but the number of ACLs increases leading to higher management complexity

Engineering Contradiction:
Improveaccess control capabilityVSAvoidnumber of ACLs
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate ACLs into a single RBACL that handles access control for multiple roles. Instead of maintaining separate ACLs for different IP addresses or roles, the system uses one unified RBACL that processes role tags, reducing the number of ACLs from multiple to one while preserving access control versatility

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9088437B2Method and device for processing source role information
Publication Date: 2015.07.21 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9088437B2 patent drawing
  • US9088437B2 patent drawing
  • US9088437B2 patent drawing

AI summary

A method and device for processing source role information in which a source role tag is inserted into a packet as an inner VLAN tag of the packet and used to perform role based access control processing for the packet.