Telecom Management Entity Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in managing entity access for applications, particularly in determining whether an application is enabled to access management or managed entities within telecom management systems, which affects the efficient deployment and management of network resources.

Innovation Solution

A method and apparatus that receive an application registry request, determine the appropriate management or managed entities, and configure access to enable the application to access these entities, involving a processor and communication protocols to authenticate and authorize the application's access to management services and data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If application registry requests are processed without centralized management, then deployment speed improves, but security and access control reliability deteriorate

Engineering Contradiction:
Improvedeployment speedVSAvoidaccess control reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary registration and authorization actions where applications must register with the management entity before accessing managed entities. The management entity pre-establishes access policies, authentication credentials, and authorization rules during the registration phase, enabling subsequent rapid access decisions without compromising security. This preliminary setup resolves the contradiction by preparing access control mechanisms in advance, allowing both fast deployment and reliable security enforcement.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If detailed access control policies are implemented, then security improves, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management entity as an intermediary between applications and managed entities. This intermediary centralizes the implementation of complex access control policies, authentication mechanisms, and authorization logic. Applications interact with the simplified management entity interface, while the management entity handles the complexity of security policy enforcement, credential verification, and access decision-making. This intermediary approach maintains high security while reducing the complexity burden on individual components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple management entities are introduced for fine-grained control, then access control precision improves, but information loss increases due to distributed management

Engineering Contradiction:
Improveaccess control precisionVSAvoidinformation loss
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent merges the functions of multiple management entities into a single centralized management entity that maintains comprehensive information about all managed entities and their access policies. This unified management entity consolidates authentication credentials, authorization rules, and entity relationships in one location, preventing information loss that would occur with distributed management. The centralized entity can still provide fine-grained access control by maintaining detailed policy information, thus resolving the contradiction between access control precision and information completeness.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20230412608A1Entity access for an application
Publication Date: 2023.12.21 LENOVO (SINGAPORE) PTE LTD
  • US20230412608A1 patent drawing
  • US20230412608A1 patent drawing
  • US20230412608A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for entity access for an application. One method includes receiving, by a first entity, an application registry request for at least one application. The method includes determining whether the at least one application is enabled to access at least one management entity or at least one managed entity.