Trust-Based Dynamic Access Control for Granular Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional networks face challenges in managing user access to network resources due to increased risk from broad access via VPNs, complex network management, and lack of client control over authorization processes, especially in distributed environments, leading to poor user experience and inefficient policy updates.
Innovation Solution
A dynamic access control system (DACS) that enables clients to define custom access policies based on trust information from multiple sources, including directly connected and out-of-band trust providers, and utilizes a trust broker and policy engine to manage fine-grained network access and routing, allowing clients to integrate their security data into the authentication and authorization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If broad network access via VPN is provided to support distributed operations, then network connectivity and user access capability are improved, but security risk and system vulnerability increase
Solution Approach 1:
The patent segments the network into multiple network segments and divides access control into granular policies. Instead of providing broad VPN access to the entire network, users are assigned access to specific network segments based on their roles and trust levels. This segmentation allows distributed operations while limiting the attack surface and security risk exposure.
Solution Approach 2:
The patent implements local quality by applying different access control policies to different network segments and resources. Each resource or network segment has customized access requirements and trust criteria. This allows the system to provide appropriate access levels locally rather than uniform broad access, maintaining security while enabling necessary connectivity.
2Reliability
If traditional VPN-based access control is used, then network connectivity is maintained, but policy update efficiency and client control capability deteriorate
Solution Approach 1:
The patent implements dynamic access control policies that can be updated in real-time without requiring VPN reconfiguration or network changes. The policy engine allows administrators to modify access policies dynamically, and changes are immediately enforced. This maintains reliable network connectivity while dramatically improving policy update efficiency compared to static VPN-based systems.
Solution Approach 2:
The patent introduces a policy engine as an intermediary between the network infrastructure and access control requirements. This intermediary layer handles policy evaluation and enforcement independently of the underlying network connectivity mechanism. Administrators can update policies through this intermediary without affecting network stability, enabling efficient policy management while maintaining reliable connectivity.
3Ease of operation
If centralized authorization control is implemented, then security management is simplified, but system complexity and deployment difficulty increase
Solution Approach 1:
The patent implements a universal trust evaluation framework that works across multiple network segments, resources, and authentication methods. The same policy engine and trust evaluation mechanisms are used throughout the system regardless of the specific resource or access method. This provides simplified centralized authorization management while avoiding the complexity of implementing separate control systems for different scenarios.
Solution Approach 2:
The patent enables self-service authentication and authorization where clients can independently evaluate trust criteria and obtain access tokens without complex centralized intervention. The policy engine provides self-service capabilities for policy evaluation, and clients can autonomously determine their access rights based on published policies. This simplifies authorization management while reducing the operational complexity of centralized control.
Data Source
AI summary
Systems and methods are provided for creating and running an instance of a dynamic access control system (DACS). Trust providers may be defined in a trust broker of the DACS such that trust information associated with the trust providers can be used to create a custom data structure. Resources and resource groups may be defined in the DACS. Policies may be configured or coded in the DACS to map the custom data structure to recourses or resources groups. Additionally, policies may be configured or coded in the DACS to route the data structure and request to network segments or shared with other parties.


