Cloud-Based Network Access Control for Devices Outside Private Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Access Control (NAC) systems lack visibility and control over devices when they are decoupled from private networks, leaving resources on these devices vulnerable to compromise.

Innovation Solution

A cloud-based security system detects malicious activity on remote devices and instructs a local agent to perform security measures, such as quarantining or disconnecting from networks, to protect resources from compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional NAC systems are used to control network access, then devices on private networks are protected, but devices outside private networks lack visibility and control

Engineering Contradiction:
Improvesecurity protectionVSAvoidcoverage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A cloud-based security system acts as an intermediary between private NAC systems and remote devices outside the network. The cloud system receives security information from multiple sources, performs centralized analysis, and distributes control decisions to remote agents on devices, enabling unified security management across network boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions from traditional network-centric security ( confined to private network boundaries) to a cloud-based dimension that operates independently of network location. By moving security intelligence to the cloud, the system gains the ability to monitor and control devices regardless of their physical network attachment, adding a spatial dimension to security coverage.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If cloud-based security systems are implemented to monitor remote devices, then visibility and control over external devices are achieved, but system complexity increases

Engineering Contradiction:
Improvecoverage scopeVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional components: cloud-based information collection modules, centralized security analysis engines, and lightweight remote agents on devices. Each component handles specific tasks independently, reducing overall system complexity while maintaining comprehensive security coverage across distributed devices.

Inventive Principle:
Principle #1Segmentation

3Reliability

If real-time security monitoring is performed on remote devices, then malicious activity is detected promptly, but information processing requirements increase

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Complex security analysis computations are extracted from resource-constrained remote devices and performed instead in cloud-based security systems. Remote agents on devices collect and transmit security information to the cloud, where powerful servers perform intensive threat analysis, reducing the computational burden on individual devices while maintaining real-time detection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12407697B2Network access control from anywhere
Publication Date: 2025.09.02 FORESCOUT TECHNOLOGIES INC
  • US12407697B2 patent drawing
  • US12407697B2 patent drawing
  • US12407697B2 patent drawing

AI summary

Systems, methods, and related technologies for managing network access control from anywhere are described. A method includes receiving, from a cloud-based security system, information about a device that is coupled to a public network and decoupled from a private network. Based on the information, the method detects risky activity associated with the device. The method sends instructions to a remote agent executing on the device to perform one or more security measures that protect a resource of the device.