Communication Control Apparatus for Network Access Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing network access control systems, as described in Patent Literature 1, are inadequate for executing supplementary controls such as checking IP packet payload and storing communication records, lacking the necessary mechanisms for generating communication paths that support these functions.
Innovation Solution
A communication control apparatus and method that generate and control communication paths based on a control policy including access control and supplementary controls, using a communication path generation unit to create paths through relay apparatuses that execute access control and supplementary controls like payload checking and record storage, and a communication path control unit to instruct relay apparatuses on these paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing network access control systems are used, then access permission control can be executed, but supplementary control such as checking communication data and storing communication records cannot be executed
Solution Approach 1:
The patent applies multi-functionality by enabling the network access control system to perform not only access permission control but also supplementary controls including checking communication data, storing communication records, and other security functions through a unified control apparatus that generates comprehensive control policies
Solution Approach 2:
The patent segments the control functionality by separating access control policies from supplementary control policies, allowing each type of control to be independently configured and executed through dedicated relay apparatuses while maintaining system-wide coordination
2Reliability
If special network relay apparatuses are added to execute supplementary control, then security control capability is improved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent introduces a communication control apparatus as an intermediary that acts as a central coordinator between the access control system and supplementary control functions. This mediator generates comprehensive control policies and distributes them to appropriate relay apparatuses, simplifying the overall system configuration while maintaining enhanced security capabilities
Solution Approach 2:
The patent merges access control and supplementary control into a unified control framework where a single communication control apparatus manages both types of controls through integrated control policies, reducing the need for separate configuration systems and lowering overall device complexity
3Adaptability or versatility
If multiple relay apparatuses are used for supplementary control, then control functionality is improved, but difficulty in setting and controlling rules for each apparatus increases
Solution Approach 1:
The communication control apparatus serves as an intermediary that automatically generates and distributes control rules to multiple relay apparatuses based on a unified control policy, eliminating the need for manual configuration of each individual apparatus and significantly improving ease of operation
Solution Approach 2:
The system enables self-service by allowing the communication control apparatus to automatically generate, distribute, and update control rules across multiple relay apparatuses without requiring manual intervention for each device, reducing operational complexity while maintaining versatile supplementary control capabilities
Data Source
AI summary
A communication control apparatus controls communication between a first apparatus and a second apparatus connected to the first apparatus via a plurality of relay apparatuses. The communication control apparatus comprises: a communication path generation unit that refers to a control policy including access control and supplementary control that is other than the access control from the first apparatus to the second apparatus and refers to network configuration information about a network configuration among the first apparatus, the second apparatus, and the plurality of relay apparatuses and generates a communication path that matches the control policy from the first apparatus to the second apparatus and goes through at least one of the plurality of relay apparatuses; and a communication path control unit that instructs a relay apparatus(es) on the communication path among the plurality of relay apparatuses to execute the access control and the supplementary control included in the control policy.


