Virtual Network Function for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems require specialized software on client devices and manual reconfiguration of DNS servers, making them inefficient and difficult to manage, especially in large networks, and they lack granular control at the device or user level.

Innovation Solution

A system that dynamically manages network access by using virtual network functions to distribute policies across multiple devices, allowing for granular control at the domain, network, and application layers without the need for specialized software clients, and updates policies in real-time to restrict access based on device information and user behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized software clients are implemented in access devices to control network access, then access control functionality is achieved, but device complexity and installation requirements increase

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsoftware client requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control logic from client devices and places it in the network infrastructure. The virtual network function (VNF) in the network cloud stores and enforces access policies, while access devices simply forward requests to the VNF. This eliminates the need for specialized software clients on access devices while maintaining access control functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a virtual network function (VNF) as an intermediary between access devices and the network resources. The VNF receives access requests from access devices, consults stored policies, and returns authorization decisions. This intermediary approach allows access control without requiring complex software on client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual reconfiguration of DNS servers is performed to update access policies, then policy updates are achieved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvepolicy update capabilityVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements dynamic policy storage in the virtual network function, allowing access control policies to be updated in real-time without manual DNS reconfiguration. The VNF maintains a database of policies that can be dynamically modified based on current network conditions, organizational requirements, or security threats, eliminating the need for time-consuming manual DNS updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent pre-stores access control policies in the virtual network function before they are needed. When access requests are made, the VNF retrieves relevant policies from its pre-loaded database, enabling rapid decision-making without requiring real-time manual policy configuration or DNS reconfiguration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If enterprise-wide policies are applied to control network access, then security is improved, but granular control at device or user level is lost

Engineering Contradiction:
Improvenetwork securityVSAvoidgranular control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control policies into multiple categories stored in the virtual network function, including enterprise-wide policies, department-specific policies, and device-level policies. This segmentation allows the system to apply different levels of control: broad enterprise policies for general security and granular device-specific policies for detailed access management, combining both security and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables different quality levels of control for different parts of the network. While enterprise-wide policies provide baseline security for all devices, the system also allows local quality control at departmental or device levels. The VNF can apply stricter or more relaxed policies based on the specific characteristics of each device or user group, achieving granular control without compromising overall security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11336696B2Control access to domains, servers, and content
Publication Date: 2022.05.17 AT&T INTELLECTUAL PROPERTY I L P
  • US11336696B2 patent drawing
  • US11336696B2 patent drawing
  • US11336696B2 patent drawing

AI summary

A system to control access to domains, servers, or content, among other things. There may be individualized or global policies. Policy servers or other devices may interface with databases, DNS servers, firewalls, programmable virtualized routers, or dynamic host configuration protocol servers, among other devices to dynamically update various policy enforcement elements.