Cloud Device Fingerprinting for Dynamic Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Network Access Control (NAC) systems are static, limited in scope, and ineffective in managing mobile devices accessing network resources from diverse operating systems and uncontrolled network topologies, leading to compatibility issues and increased security risks due to inadequate risk profiling and device identification.
Innovation Solution
A cloud-based security system employs multidimensional risk profiling and dynamic device fingerprinting using hardware parameters to generate a unique identifier for mobile devices, enabling adaptive risk analysis and unified service discovery for secure network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional static NAC systems are used, then system simplicity is maintained, but security effectiveness and adaptability to mobile devices deteriorate
Solution Approach 1:
The patent implements dynamic device fingerprinting that continuously updates device identifiers based on real-time hardware parameter changes, enabling the NAC system to adapt to mobile devices' changing network topologies and configurations while maintaining security effectiveness
Solution Approach 2:
The system changes the parameters used for device identification from static IP addresses to dynamic hardware-based fingerprints that incorporate multiple hardware parameters, allowing the system to effectively identify and profile mobile devices across diverse operating systems and network conditions
2Measurement precision
If device fingerprinting using hardware parameters is implemented, then device identification accuracy improves, but system complexity increases
Solution Approach 1:
The patent creates a universal device fingerprinting mechanism that works across diverse operating systems and mobile devices by using hardware parameters that are commonly available, making the system both accurate and broadly applicable without requiring device-specific implementations
Solution Approach 2:
The system introduces a cloud-based security system as an intermediary that handles the complex processing of hardware parameters and fingerprint generation, reducing the complexity burden on individual NAC components while maintaining high identification accuracy
3Reliability
If multidimensional risk profiling is performed, then security risk detection improves, but processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary device fingerprinting and hardware parameter collection during device enrollment and initial connection, preparing risk profiling data in advance so that subsequent security decisions can be made quickly without real-time processing delays
Solution Approach 2:
The system enables mobile devices to self-profile by automatically reporting their own hardware parameters and risk characteristics, reducing the computational burden on the NAC system while maintaining comprehensive multidimensional risk assessment capabilities
Data Source
AI summary
Systems and methods for device identification for management and policy in the cloud, using a combination of several hardware parameters and user's identification to generate a unique identifier for a user device and associated user. IOCTL and Assembly can be used to get the different hardware parameters. All the hardware parameters can then run through a process to generate a fixed size hardware fingerprint. A base64 encoding can be performed to convert it into a string, for consumption of database. The resultant identifier is unique and it is never stored on machine. The application can simply generate it whenever needed. The resultant identifier can used by a service provider to uniquely identify the device even when the device is moving hands or locations. The resultant identifier is never stored, so moving data from one device to another will not result in the same identifier for two devices.


