Network Switch Access Control via User Role Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network switch devices often lack effective access control mechanisms, leading to potential unauthorized access and security risks when shared among multiple users, as existing systems do not adequately restrict access to ports and configuration settings based on user roles and access levels.

Innovation Solution

A method and apparatus for providing user access to network switch appliances, where access is determined by user identification and assigned access levels, allowing users to access specific network and instrument ports, and perform specific tasks, with access levels defined and stored in a non-transitory medium, such as a database, to ensure controlled access and configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network switch devices are shared by multiple users, then device utilization and productivity are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvedevice utilizationVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments user access rights by creating distinct access levels (e.g., read-only, read-write, administrative) and assigning specific users to particular access levels. This segmentation allows multiple users to simultaneously utilize the network switch device while each user's operations are constrained to their authorized scope, thereby maintaining security while enabling shared productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by providing different access permissions to different users based on their specific needs and roles. Rather than applying a uniform access policy to all users, the system tailors access rights individually or in groups, allowing each user to have appropriate-level access to specific device functions and configuration parameters.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If access control mechanisms are implemented to restrict user access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent achieves universality by implementing a centralized access control framework that handles multiple functions through a unified mechanism. The access level assignment system serves as a universal controller that manages authentication, authorization, and permission enforcement across all device operations, simplifying the overall complexity despite the comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies parameter changes by introducing access level as a controllable parameter that can be adjusted to modify user permissions. By changing the access level parameter assigned to users, the system can dynamically control the degree of access without restructuring the entire access control mechanism, thereby managing complexity through parameterization.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If user access levels are assigned and stored in non-transitory medium, then access control reliability is improved, but storage requirements and device complexity increase

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent employs copying by storing access level assignments in a non-transitory medium (such as a database or configuration file) that can be replicated and backed up. This ensures reliable persistence of access control data while allowing the actual storage implementation to be optimized separately from the control logic.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the access level assignment data from the core device operation logic and stores it separately in a non-transitory medium. This extraction allows the access control reliability to be maintained through persistent storage while minimizing the impact on device complexity and storage requirements by separating data from processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11025639B2Security access for a switch device
Publication Date: 2021.06.01 GIGAMON INC
  • US11025639B2 patent drawing
  • US11025639B2 patent drawing
  • US11025639B2 patent drawing

AI summary

A method for providing user access to a network switch appliance, includes: receiving from a user a request to access configuration item for the network switch appliance, the network switch appliance configured to pass packets received from a network to network monitoring instruments; and determining, using a processing unit, whether to allow the user to access the configuration item for the network switch appliance based on information regarding the user.