Role-Based Message Authorization in Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer network systems lack effective mechanisms to control message communication between user devices based on predefined user roles, leading to unauthorized exchanges.
Innovation Solution
Implementing a system where network devices receive messages, identify user roles, and determine if predefined user role relationships authorize communication, refraining from forwarding messages if authorization is not granted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If messages are blocked based on IP address, then unauthorized communication can be prevented, but the control mechanism lacks flexibility and cannot enforce user role-based permissions
Solution Approach 1:
The patent changes the blocking parameter from IP address to user role. The network device identifies user roles associated with source and destination devices and enforces communication policies based on role relationships rather than fixed IP addresses, providing both security and flexibility
Solution Approach 2:
The patent introduces dynamic role-based access control where permissions are determined by user roles and their relationships rather than static IP configurations. The system can adapt to different users and devices based on their assigned roles, making the control mechanism flexible and adaptable
2Adaptability or versatility
If user role-based control is implemented, then communication can be precisely controlled according to user roles, but the system complexity increases due to role identification and relationship determination
Solution Approach 1:
The patent introduces an intermediary mechanism where the network device acts as a mediator between users and the communication channel. It automatically performs role identification and relationship determination, shielding users from the complexity while enabling precise role-based control
Solution Approach 2:
The system implements self-service by automatically identifying user roles and determining authorization based on predefined role relationships. The network device autonomously makes authorization decisions without requiring manual intervention, reducing operational complexity
Data Source
AI summary
A non-transitory computer readable medium includes instructions which, when executed by one or more hardware processors, causes performance of operations. The operations include receiving, by a network device from a first user device, a first message addressed to a second user device and identifying a first user role associated with the first user device and a second user role associated with the second user device. The operations further include determining whether a set of predefined user role relationships authorizes a communication between user devices having the first user role and user devices having the second user role. In response to determining that the set of predefined user role relationships do not authorize the communication between user devices having the first user role and user devices having the second user role, the operations refrain forwarding the first message from the first user device to the second user device.


