Unified Trust and Identity Policy System for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control frameworks are complex and fragmented, leading to inconsistent and incorrect enforcement when multiple frameworks are deployed together, requiring administrators to manage separate policy decision points and handle diverse client and protocol types, which complicates unified policy configuration and enforcement.

Innovation Solution

A Unified Trust and Identity Policy System (UTIPS) that integrates multiple network access control frameworks by using a client protocol terminator, access attribute translation device, and policy database to translate attributes into a canonical form, allowing for unified policy decisions and seamless handling of different frameworks and protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple network access control frameworks are deployed to meet disparate assessment and operating requirements, then the system can support diverse clients and protocols, but the device complexity and difficulty of unified policy configuration increase significantly

Engineering Contradiction:
Improvesupport for diverse clients and protocolsVSAvoidcomplexity of managing multiple PDPs
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple framework-specific PDPs into a single unified PDP that can handle multiple frameworks (Cisco NAC, Microsoft NAP, TNC) simultaneously. This consolidation reduces the number of separate policy decision points from multiple to one, while maintaining support for diverse clients and protocols through framework-specific protocol terminators that translate to a common internal representation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified PDP is designed with multi-functionality to handle multiple NAC frameworks through a single device. It implements framework-specific protocol terminators for different access protocols (802.1x, EAPoUDP, VPN) and frameworks, translating all to a common internal attribute representation, thus providing universal policy enforcement across diverse network access scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If framework-specific PDPs are used for each NAC framework, then each framework can be enforced correctly, but the ease of operation for unified policy configuration deteriorates

Engineering Contradiction:
Improvecorrect enforcement of each frameworkVSAvoidunified policy configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces framework-specific protocol terminators as intermediary components between the external NAC frameworks and the unified PDP. These terminators translate framework-specific attributes and protocols into a common internal representation, allowing the unified PDP to enforce multiple frameworks correctly without requiring administrators to configure separate PDPs for each framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple NAC frameworks are deployed with segmented assessments, then each framework can handle specific assessments, but the loss of time for policy management and coordination increases

Engineering Contradiction:
Improvespecialized assessment capabilityVSAvoidtime for policy management and coordination
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the policy management functionality of multiple frameworks into a single unified PDP that can handle all assessments (client software validation, health checks, firewall configuration) across all frameworks simultaneously. This eliminates the need for administrators to separately manage and coordinate policies across multiple PDPs, reducing policy management time while maintaining specialized assessment capabilities through framework-specific protocol terminators.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8713639B2Method and apparatus for policy-based network access control with arbitrary network access control frameworks
Publication Date: 2014.04.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8713639B2 patent drawing
  • US8713639B2 patent drawing
  • US8713639B2 patent drawing

AI summary

A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.