Access Controller HTML Authentication for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access controllers in communications networks fail to provide a secure method for users to enter credentials before accessing a public IP network, making it difficult to detect 'man-in-the-middle' attacks and do not adequately restrict access to non-authenticated users.

Innovation Solution

An access controller system that presents a service announcement page to users, allowing them to retrieve a login page if authentication is required, with verified credentials checked against an AAA server or a locally defined list, granting access only after successful verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current access controllers automatically redirect users to a portal page, then network access control is provided, but security is compromised and man-in-the-middle attacks cannot be detected

Engineering Contradiction:
Improvenetwork access controlVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an HTML authentication mechanism as an intermediary between the access controller and the user's computing device. This intermediary presents a service announcement page that alerts users to potential security risks and provides a secure login interface, thereby detecting and preventing man-in-the-middle attacks while maintaining network access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security verification by presenting the service announcement page and requiring user credentials before granting network access. This preliminary action allows the access controller to verify the user's device and credentials in advance, detecting potential attacks before they can compromise the network.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access controllers redirect users to portal pages, then access restriction is achieved, but user experience is degraded

Engineering Contradiction:
Improveaccess restrictionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The HTML authentication serves as a user-friendly intermediary that presents information in a familiar web browser interface rather than a technical portal redirect. The service announcement page clearly explains authentication requirements and provides an intuitive login form, improving user experience while maintaining access restriction.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If authentication is required before network access, then security is improved, but access time is increased

Engineering Contradiction:
Improveunauthorized accessVSAvoidauthentication time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system enables users to perform self-service authentication by presenting credentials through a familiar web browser interface. Users can independently complete the authentication process without requiring technical assistance or complex portal navigation, reducing authentication time while maintaining security against unauthorized access.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8046578B1System and method for providing HTML authentication using an access controller
Publication Date: 2011.10.25 MARQETA INC
  • US8046578B1 patent drawing
  • US8046578B1 patent drawing
  • US8046578B1 patent drawing

AI summary

A system and method for granting access to a computer network. The method may include, for example, receiving at an access controller a request by a user to access the network using a computing device; providing the user with the option to retrieve a login page if authentication is required prior to network access being granted; using the access controller to verify user credentials provided by the user on the login page, the using the access controller to verify user credentials comprising: comparing a source IP address of a transmission control protocol connection request with a locally defined list of authorized user credentials stored in the access controller; and determining whether a White List associated with the access controller comprises a destination IP address; and granting the user access to the network if the user credentials are verified.