Unified Trust and Identity Policy System for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control frameworks are complex and fragmented, leading to inconsistent and incorrect enforcement when multiple frameworks are deployed together, requiring administrators to manage separate policy decision points and handle diverse client and protocol types, which complicates unified policy configuration and enforcement.
Innovation Solution
A Unified Trust and Identity Policy System (UTIPS) that integrates multiple network access control frameworks by using a client protocol terminator, access attribute translation device, and policy database to translate attributes into a canonical form, allowing for unified policy decisions and seamless handling of different frameworks and protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple network access control frameworks are deployed to meet disparate assessment and operating requirements, then the system can support diverse clients and protocols, but the device complexity and difficulty of unified policy configuration increase significantly
Solution Approach 1:
The patent merges multiple framework-specific PDPs into a single unified PDP that can handle multiple frameworks (Cisco NAC, Microsoft NAP, TNC) simultaneously. This consolidation reduces the number of separate policy decision points from multiple to one, while maintaining support for diverse clients and protocols through framework-specific protocol terminators that translate to a common internal representation.
Solution Approach 2:
The unified PDP is designed with multi-functionality to handle multiple NAC frameworks through a single device. It implements framework-specific protocol terminators for different access protocols (802.1x, EAPoUDP, VPN) and frameworks, translating all to a common internal attribute representation, thus providing universal policy enforcement across diverse network access scenarios.
2Reliability
If framework-specific PDPs are used for each NAC framework, then each framework can be enforced correctly, but the ease of operation for unified policy configuration deteriorates
Solution Approach 1:
The patent introduces framework-specific protocol terminators as intermediary components between the external NAC frameworks and the unified PDP. These terminators translate framework-specific attributes and protocols into a common internal representation, allowing the unified PDP to enforce multiple frameworks correctly without requiring administrators to configure separate PDPs for each framework.
3Reliability
If multiple NAC frameworks are deployed with segmented assessments, then each framework can handle specific assessments, but the loss of time for policy management and coordination increases
Solution Approach 1:
The patent merges the policy management functionality of multiple frameworks into a single unified PDP that can handle all assessments (client software validation, health checks, firewall configuration) across all frameworks simultaneously. This eliminates the need for administrators to separately manage and coordinate policies across multiple PDPs, reducing policy management time while maintaining specialized assessment capabilities through framework-specific protocol terminators.
Data Source
AI summary
A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.


