Communication Control Apparatus for Network Access Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing network access control systems, as described in Patent Literature 1, are inadequate for executing supplementary controls such as checking IP packet payload and storing communication records, lacking the necessary mechanisms for generating communication paths that support these functions.

Innovation Solution

A communication control apparatus and method that generate and control communication paths based on a control policy including access control and supplementary controls, using a communication path generation unit to create paths through relay apparatuses that execute access control and supplementary controls like payload checking and record storage, and a communication path control unit to instruct relay apparatuses on these paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing network access control systems are used, then access permission control can be executed, but supplementary control such as checking communication data and storing communication records cannot be executed

Engineering Contradiction:
Improvecontrol functionalityVSAvoidsecurity control capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies multi-functionality by enabling the network access control system to perform not only access permission control but also supplementary controls including checking communication data, storing communication records, and other security functions through a unified control apparatus that generates comprehensive control policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the control functionality by separating access control policies from supplementary control policies, allowing each type of control to be independently configured and executed through dedicated relay apparatuses while maintaining system-wide coordination

Inventive Principle:
Principle #1Segmentation

2Reliability

If special network relay apparatuses are added to execute supplementary control, then security control capability is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a communication control apparatus as an intermediary that acts as a central coordinator between the access control system and supplementary control functions. This mediator generates comprehensive control policies and distributes them to appropriate relay apparatuses, simplifying the overall system configuration while maintaining enhanced security capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges access control and supplementary control into a unified control framework where a single communication control apparatus manages both types of controls through integrated control policies, reducing the need for separate configuration systems and lowering overall device complexity

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple relay apparatuses are used for supplementary control, then control functionality is improved, but difficulty in setting and controlling rules for each apparatus increases

Engineering Contradiction:
Improvesupplementary control capabilityVSAvoidrule configuration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The communication control apparatus serves as an intermediary that automatically generates and distributes control rules to multiple relay apparatuses based on a unified control policy, eliminating the need for manual configuration of each individual apparatus and significantly improving ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the communication control apparatus to automatically generate, distribute, and update control rules across multiple relay apparatuses without requiring manual intervention for each device, reducing operational complexity while maintaining versatile supplementary control capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9288233B2Communication control apparatus, communication control method, and program
Publication Date: 2016.03.15 NEC ASIA PACIFIC PTE LTD
  • US9288233B2 patent drawing
  • US9288233B2 patent drawing
  • US9288233B2 patent drawing

AI summary

A communication control apparatus controls communication between a first apparatus and a second apparatus connected to the first apparatus via a plurality of relay apparatuses. The communication control apparatus comprises: a communication path generation unit that refers to a control policy including access control and supplementary control that is other than the access control from the first apparatus to the second apparatus and refers to network configuration information about a network configuration among the first apparatus, the second apparatus, and the plurality of relay apparatuses and generates a communication path that matches the control policy from the first apparatus to the second apparatus and goes through at least one of the plurality of relay apparatuses; and a communication path control unit that instructs a relay apparatus(es) on the communication path among the plurality of relay apparatuses to execute the access control and the supplementary control included in the control policy.