Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

104 results about "Network Admission Control" patented technology

Network Admission Control (NAC) refers to Cisco's version of Network Access Control, which restricts access to the network based on identity or security posture. When a network device (switch, router, wireless access point, DHCP server, etc.) is configured for NAC, it can force user or machine authentication prior to granting access to the network. In addition, guest access can be granted to a quarantine area for remediation of any problems that may have caused authentication failure. This is enforced through an inline custom network device, changes to an existing switch or router, or a restricted DHCP class. A typical (non-free) WiFi connection is a form of NAC. The user must present some sort of credentials (or a credit card) before being granted access to the network.

Call admission control for Wi-Fi

Call admission control within a wireless network is implemented using a service controller that manages a set of access points. The call admission control (CAC) function for a given access point determines whether the access point has sufficient unused bandwidth to handle an additional call. The service controller makes this determination by monitoring the access points and evaluating certain probability functions and load conditions. In one embodiment, a determination of whether the access point has sufficient unused bandwidth to handle an additional call is a function of two (2) independent probabilities: (i) a probability of an active session moving to the access point from one or more neighbor access points, and (ii) a probability of an idle mobile device already associated with the access point entering into a new active session by initiating an inbound or outbound call. According to another aspect, the service controller issues and manages “call admission credits” among the set of access points, where a call admission credit value indicates a number of calls that idle mobile devices associated with the access point may initiate from the AP. The call admission credits value is a function of a determined load on the AP, and a mobility probability, which is a probability of an active call moving to the access point from one or more neighbor access points. The call admission credit value for the access point is adjusted as a function of a change of the load or in the mobility probability.
Owner:VALTRUS INNOVATIONS LTD +1

Equipment identification system based on equipment fingerprint

The invention belongs to the field of network admission control technology, and particularly relates to an equipment identification system based on an equipment fingerprint, wherein the equipment fingerprint information comprises hardware information, operating system information and application service information of the equipment. The system comprises the components of an equipment fingerprint database, an equipment discovery module, an equipment fingerprint acquisition module, an equipment fingerprint processing module, an equipment fingerprint matching module and an artificial identification module. The equipment fingerprint information comprises the MAC OUI hardware information and the operating system information of the equipment and the application service information in a port list. The formats of the fingerprint database comprise MAC OUI, operating system information, port list and equipment type. The equipment fingerprint acquisition module comprises operating system fingerprint information and port fingerprint information. The equipment identification system has advantages of performing network admission control on network equipment through the equipment type, making different security strategies on different kinds of equipment, preventing equipment counterfeiting, and ensuring high safety of enterprise network.
Owner:BEIJING VRV SOFTWARE CO LTD

Intranet security unified management platform and management method of management platform

ActiveCN103179130AImplement access controlAvoid simultaneous access to the networkNetworks interconnectionWeb authenticationMulti dimensional
The invention discloses an intranet security unified management platform and a management method of the management platform. The intranet security unified management platform comprises an admission standard management system, an intelligent network management system and a multi-dimensional terminal security management platform. The management method comprises the steps of: carrying out feature identification on a terminal accessing to a network; carrying out query according to a feature of the terminal, taking an admission role; carrying out standard examination on the role to access the network according to the role authority; carrying out monitoring and irregularity response on security configuration and operation behaviors after the terminal accesses the network; carrying out monitoring and irregularity response on flow condition of the network; and carrying out statistics and BI (Business Intelligence) analysis on various kinds of events. According to the intranet security unified management platform and the management method of the management platform, admission control is realized through switching of an isolation region, the transmission of all data of a device in the isolation region is controlled through the management platform, the standard restriction is realized through a WEB authentication page on which the an access device is forced to access the management platform, and thus the non-client end admission control is realized, and the defect that a plurality of devices under a single port are simultaneously accessed to the network or simultaneously isolated is avoided.
Owner:HANGZHOU INFOGO TECH

Network access control system

The invention is applicable to the field of network security, and provides a network access control system. The network access control system comprises an access authentication client, a network access control gateway and an authentication server, wherein the access authentication client is arranged at an access terminal and is used for authenticating network resource access of the access terminal; the network access control gateway is accessed to a node on a key path in which the access terminal accesses network resources, and is used for initiating authentication to the access terminal of accessing the network resources and controlling the network resource access of the access terminal according to an authentication state of the access terminal; the authentication server is used for issuing a security policy to the access authentication client, checking an identity of the access authentication client and a checking state of the security policy, and issuing a corresponding network resource access control instruction to the network access control gateway. According to the network access control system, network access control is realized by adopting a gateway manner, and a user does not need to completely replace network equipment such as all access layer network switches; the network access control system is simple to implement, and low in purchasing and implementing costs.
Owner:GUIZHOU POWER GRID CO LTD ZUNYI POWER SUPPLY BUREAU

Network admission control method and system

The invention provides a network admission control method and system, and relates to the technical field of network security, and the method comprises the steps: detecting a real-time online terminalin a network; performing security auditing on the real-time online terminal according to a basic database; if the real-time online terminal passes the security auditing, permitting the real-time online terminal to access the network; if the real-time online terminal does not pass the security audit, performing security authentication on the real-time online terminal according to the basic data if the real-time online terminal passes the security authentication, permitting the real-time online terminal to access the network, and setting a first access permission; if the real-time online terminal does not pass the security authentication, performing security evaluation on the real-time online terminal according to the basic data if the real-time online terminal passes the securityevaluation, permitting the real-time online terminal to access the network, and setting a second access permission; and if the real-time online terminal does not pass the security assessment, refusingthe real-time online terminal to enter the network. According to the invention, multiple verification is carried out on the authenticity of the user identity and the terminal risk, network admissioncontrol and access permission acquisition are realized, and the network security is improved.
Owner:上海文化广播影视集团有限公司 +1
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products