Role-Based Message Authorization in Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network systems lack effective mechanisms to control message communication between user devices based on predefined user roles, leading to unauthorized exchanges.

Innovation Solution

Implementing a system where network devices receive messages, identify user roles, and determine if predefined user role relationships authorize communication, refraining from forwarding messages if authorization is not granted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If messages are blocked based on IP address, then unauthorized communication can be prevented, but the control mechanism lacks flexibility and cannot enforce user role-based permissions

Engineering Contradiction:
Improvecommunication securityVSAvoidcontrol flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the blocking parameter from IP address to user role. The network device identifies user roles associated with source and destination devices and enforces communication policies based on role relationships rather than fixed IP addresses, providing both security and flexibility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic role-based access control where permissions are determined by user roles and their relationships rather than static IP configurations. The system can adapt to different users and devices based on their assigned roles, making the control mechanism flexible and adaptable

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If user role-based control is implemented, then communication can be precisely controlled according to user roles, but the system complexity increases due to role identification and relationship determination

Engineering Contradiction:
Improverole-based controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the network device acts as a mediator between users and the communication channel. It automatically performs role identification and relationship determination, shielding users from the complexity while enabling precise role-based control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service by automatically identifying user roles and determining authorization based on predefined role relationships. The network device autonomously makes authorization decisions without requiring manual intervention, reducing operational complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9917839B2Communication model based on user role
Publication Date: 2018.03.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9917839B2 patent drawing
  • US9917839B2 patent drawing
  • US9917839B2 patent drawing

AI summary

A non-transitory computer readable medium includes instructions which, when executed by one or more hardware processors, causes performance of operations. The operations include receiving, by a network device from a first user device, a first message addressed to a second user device and identifying a first user role associated with the first user device and a second user role associated with the second user device. The operations further include determining whether a set of predefined user role relationships authorizes a communication between user devices having the first user role and user devices having the second user role. In response to determining that the set of predefined user role relationships do not authorize the communication between user devices having the first user role and user devices having the second user role, the operations refrain forwarding the first message from the first user device to the second user device.