User-Based Overlay Network Policy for Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network communication protocols that use IP addresses for both host identity and location create vulnerabilities to attacks like man-in-the-middle and denial of service, and pose challenges in securing modern distributed networks with ephemeral and non-unique addresses, leading to unauthorized access and policy violations.
Innovation Solution
Implementing an overlay network management system that separates host identity from topological location, using authorization services to authenticate users and enforce policies based on user groups and resource tags, ensuring secure and policy-compliant communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network addresses are used for both host identity and location, then network communication routing is simplified, but security vulnerabilities increase
Solution Approach 1:
The patent segments the dual function of network addresses into two separate functions: identity addresses and location addresses. Identity addresses are used for authentication and authorization (who the host is), while location addresses are used for routing and communication (where the host is). This segmentation resolves the contradiction by maintaining simple routing through location addresses while eliminating security vulnerabilities associated with using the same addresses for both purposes.
2Adaptability or versatility
If ephemeral and non-unique network addresses are used, then host mobility is improved, but access control becomes difficult
Solution Approach 1:
The patent separates access control from network address-based identification. Instead of relying on stable network addresses for access control, the system uses identity addresses combined with authentication mechanisms. This allows hosts to use ephemeral location addresses for mobility while maintaining reliable access control through identity verification and authorization services.
Solution Approach 2:
The patent introduces an intermediary authentication and authorization service layer between network communication and access control decisions. This intermediary verifies user identities and enforces policies independently of location address stability, enabling host mobility while maintaining reliable access control through centralized authentication services.
3Ease of operation
If network addresses provide host identity, then authentication is simplified, but network policy enforcement becomes vulnerable to spoofing
Solution Approach 1:
The patent segments authentication into two components: identity address verification and authorization policy enforcement. Identity addresses provide simplified authentication by verifying who the host claims to be, while separate authorization services enforce network policies based on authenticated identities. This segmentation prevents spoofing attacks because location addresses (which can be spoofed) are separate from the authentication process.
Solution Approach 2:
The patent introduces an intermediary authorization service that acts as a mediator between authentication and network policy enforcement. This intermediary receives authenticated identity information and makes authorization decisions independently of network address information, preventing spoofing attacks while maintaining simple authentication through identity verification.
Data Source
AI summary
Embodiments are directed to managing communication. Credentials of a user may be provided to an authorization service such that the authorization service authenticates the user as a member of authorization groups and such that the user may be associated with a gateway on an overlay network. The authorization groups may be compared with user groups to associate the user with one or more user group. The gateway may be associated with one or more resource group based on the user groups. Policy information may be generated for the gateway based on each resource group. The policy information may be provided to the gateway to define policies associated with resources in the overlay network. The policy information may be enforced against source nodes providing overlay traffic directed to target nodes in the overlay network.


