User-Based Overlay Network Policy for Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network communication protocols that use IP addresses for both host identity and location create vulnerabilities to attacks like man-in-the-middle and denial of service, and pose challenges in securing modern distributed networks with ephemeral and non-unique addresses, leading to unauthorized access and policy violations.

Innovation Solution

Implementing an overlay network management system that separates host identity from topological location, using authorization services to authenticate users and enforce policies based on user groups and resource tags, ensuring secure and policy-compliant communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network addresses are used for both host identity and location, then network communication routing is simplified, but security vulnerabilities increase

Engineering Contradiction:
Improvenetwork communication routingVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the dual function of network addresses into two separate functions: identity addresses and location addresses. Identity addresses are used for authentication and authorization (who the host is), while location addresses are used for routing and communication (where the host is). This segmentation resolves the contradiction by maintaining simple routing through location addresses while eliminating security vulnerabilities associated with using the same addresses for both purposes.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If ephemeral and non-unique network addresses are used, then host mobility is improved, but access control becomes difficult

Engineering Contradiction:
Improvehost mobilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent separates access control from network address-based identification. Instead of relying on stable network addresses for access control, the system uses identity addresses combined with authentication mechanisms. This allows hosts to use ephemeral location addresses for mobility while maintaining reliable access control through identity verification and authorization services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication and authorization service layer between network communication and access control decisions. This intermediary verifies user identities and enforces policies independently of location address stability, enabling host mobility while maintaining reliable access control through centralized authentication services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If network addresses provide host identity, then authentication is simplified, but network policy enforcement becomes vulnerable to spoofing

Engineering Contradiction:
ImproveauthenticationVSAvoidnetwork policy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments authentication into two components: identity address verification and authorization policy enforcement. Identity addresses provide simplified authentication by verifying who the host claims to be, while separate authorization services enforce network policies based on authenticated identities. This segmentation prevents spoofing attacks because location addresses (which can be spoofed) are separate from the authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authorization service that acts as a mediator between authentication and network policy enforcement. This intermediary receives authenticated identity information and makes authorization decisions independently of network address information, preventing spoofing attacks while maintaining simple authentication through identity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407738B2Applying overlay network policy based on users
Publication Date: 2025.09.02 TYCO FIRE & SECURITY GMBH
  • US12407738B2 patent drawing
  • US12407738B2 patent drawing
  • US12407738B2 patent drawing

AI summary

Embodiments are directed to managing communication. Credentials of a user may be provided to an authorization service such that the authorization service authenticates the user as a member of authorization groups and such that the user may be associated with a gateway on an overlay network. The authorization groups may be compared with user groups to associate the user with one or more user group. The gateway may be associated with one or more resource group based on the user groups. Policy information may be generated for the gateway based on each resource group. The policy information may be provided to the gateway to define policies associated with resources in the overlay network. The policy information may be enforced against source nodes providing overlay traffic directed to target nodes in the overlay network.