Shared Configuration Management for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication platforms, such as SIP, do not allow automatic or systematic sharing of network configurations between users, hindering secure and productive communication sessions in private networks.
Innovation Solution
A method and system using shared presence information to manage network access, where association and configuration information are maintained to determine associations between users and configure access points to allow or deny externally generated communications, enabling centralized storage and management of access point configurations and sharing of pinhole definitions between network endpoints and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If configuration information is manually set for each endpoint, then network security is maintained, but network management complexity increases and productivity decreases
Solution Approach 1:
The patent merges configuration information from multiple endpoints into a shared repository, allowing the network to collectively manage access rules. Instead of each endpoint maintaining separate configurations, the system combines configurations into a unified structure that can be systematically applied, reducing management complexity while maintaining security through centralized control
Solution Approach 2:
The shared configuration repository serves multiple functions: it stores access rules, maintains association information, enables automatic configuration application, and provides a basis for security decisions. This multi-functional system replaces multiple separate manual configuration processes, reducing overall network management complexity while preserving security requirements
2Productivity
If configuration information is shared between users, then network productivity improves, but network security risk increases
Solution Approach 1:
The patent introduces an intermediary system that mediates configuration sharing between users. The shared repository acts as a controlled intermediary that allows configuration information to be exchanged and applied across the network while maintaining security through systematic access control and association-based permissions, enabling productivity without direct user-to-user configuration exposure
Solution Approach 2:
The system implements feedback mechanisms where association information is continuously maintained and used to determine whether configuration information should be applied. This feedback loop ensures that configuration sharing occurs only when appropriate associations exist, automatically adjusting security decisions based on current network state and association data, thus enabling productive sharing while maintaining security boundaries
3Ease of operation
If automatic configuration application is implemented, then ease of operation improves, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing a shared configuration repository and maintaining association information in advance. When access decisions are needed, the system can quickly apply pre-configured rules based on existing associations, eliminating the need for complex real-time configuration analysis and simplifying the operational decision-making process
Solution Approach 2:
The system enables self-service by automatically applying configuration information from the shared repository based on maintained association data. The network infrastructure autonomously makes access decisions without requiring manual intervention for each configuration application, improving ease of operation while the automated processes manage the underlying system complexity
Data Source
AI summary
In accordance with a particular embodiment of the present invention, a method using shared configuration information to manage network access for externally generated communications includes maintaining association information for a first end user of a private network and maintaining configuration information for a first endpoint associated with the first end user. When an externally generated communication that is addressed for delivery to a second endpoint associated with a second end user is received at an access point to the private network, the association information is used to determine an association between the first end user and the second end user. The configuration information for the first end user is used to configure the access point to allow the communication to be delivered to the second endpoint.


