User Group Permission Matrix for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Access Control Lists (ACLs) in networks become cumbersome and costly to manage due to their reliance on static IP addresses, leading to increased complexity and the risk of network outages as networks grow and topology changes occur, necessitating a more efficient method for generating and maintaining network access control information.

Innovation Solution

The implementation of a permissions matrix system where user group identifiers (UGIs) are used to decouple security policies from network topology, allowing for the efficient generation and maintenance of access control lists by grouping users into roles and using a user group permissions matrix to simplify the management of network access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional ACLs are used to control network access, then security policies can be enforced, but the complexity and size of ACLs increases dramatically as networks grow

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidACL size and complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network access control problem by introducing user group identifiers (UGIs) that group multiple IP addresses together. Instead of managing individual IP addresses in ACLs, the system divides the network into manageable user groups, where each UGI represents a segment of users with similar access requirements. This segmentation reduces ACL complexity by replacing numerous individual IP address entries with consolidated user group references.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces user group identifiers as an intermediary layer between IP addresses and security policies. The UGI acts as a mediator that maps multiple source IP addresses to a single permission set, eliminating the need for numerous ACL entries. This intermediary structure allows the system to maintain security policy enforcement while dramatically reducing the size and complexity of ACLs by using the UGI as a shorthand reference.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ACLs are updated frequently to accommodate network changes, then security policies remain current, but processing costs and network outages increase

Engineering Contradiction:
Improvesecurity policy currencyVSAvoidnetwork operations continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-computing and caching user group permissions before they are needed for access control decisions. The system proactively generates and stores permission mappings for user groups, so when network changes occur, the pre-computed permissions can be quickly updated without triggering extensive real-time processing. This preliminary preparation reduces the computational burden during network changes and minimizes the risk of network outages.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic updating mechanisms that allow the system to adapt to network changes efficiently. The user group identifier mappings and permission sets can be dynamically updated without requiring complete ACL recompilation. This dynamic approach enables selective updates only for affected user groups, maintaining security policy currency while minimizing processing overhead and avoiding network outages.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If user-specific ACL rules are added for each authenticated user, then access control precision improves, but the number of unique ACLs increases dramatically

Engineering Contradiction:
Improveaccess control precisionVSAvoidnumber of unique ACLs
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple user-specific access control requirements into consolidated user group permission sets. Instead of creating separate ACL rules for each individual user, the system combines users with similar access needs into user groups represented by UGIs. This merging approach maintains precise access control by preserving user-specific permissions where needed while consolidating common permissions into shared user group definitions, thereby reducing the total number of unique ACLs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal user group identifier mappings that can serve multiple users and multiple access control scenarios simultaneously. A single UGI can represent multiple users and be applied across different network interfaces and contexts, providing multi-functional access control. This universality eliminates the need for duplicating user-specific ACL rules in multiple locations, reducing ACL complexity while maintaining precise access control through the reusable UGI references.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7669244B2Method and system for generating user group permission lists
Publication Date: 2010.02.23 CISCO TECHNOLOGY INC
  • US7669244B2 patent drawing
  • US7669244B2 patent drawing
  • US7669244B2 patent drawing

AI summary

A method and apparatus for generating user group identifiers using a permissions matrix is disclosed. The permissions matrix includes an entry that is associated with a row and a column of the permissions matrix. The row of the permissions matrix is indexed with a first role and the column of the permissions matrix is indexed with a second role. A data structure implementing such a method can include, for example, a user group identifier matrix. Alternatively, a method is disclosed in which the expiration of a user group identifier is detected. In such a case, the user group identifier is updated by accessing a user group identifier matrix.