Context-Aware Risk Scoring for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems lack effective methods to analyze and quantify the risk of allowing devices to access a network based on the physical context or location, which can vary and introduce different security risks.

Innovation Solution

A method and system that authenticate users and capture images of the environment to generate a device context, which is then used to determine a risk score associated with the device and its location, thereby assessing the risk of network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system captures images and analyzes device context to determine risk scores, then security risk assessment is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity risk assessmentVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the risk assessment process into distinct modules: image capture, device context generation, risk score determination, and network access control. Each module operates independently and can be implemented separately, reducing overall system complexity while maintaining comprehensive security assessment capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk assessment system that sits between the device and the network. This intermediary layer analyzes device context and determines risk scores without requiring complex integration into the core network infrastructure, thereby improving security assessment while limiting the increase in device complexity to peripheral components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system continuously monitors device context and updates risk scores, then security responsiveness is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system employs periodic action by triggering image capture and risk assessment only at specific events such as user login, device connection, or scheduled intervals. This periodic monitoring approach maintains security responsiveness while significantly reducing continuous energy consumption compared to constant monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The risk assessment system dynamically adjusts its monitoring intensity based on the determined risk score. High-risk devices trigger continuous or frequent monitoring, while low-risk devices undergo periodic checking only. This dynamic adaptation ensures security responsiveness for critical cases while minimizing overall energy consumption across the board.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If the system denies network access based on risk scores, then security threat mitigation is improved, but user convenience deteriorates

Engineering Contradiction:
Improvesecurity threat mitigationVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms that communicate risk assessments and access decisions to users. When network access is denied based on risk scores, users receive feedback with guidance on how to resolve the issue, such as providing additional authentication or contacting IT support. This feedback approach maintains security threat mitigation while improving user convenience by eliminating confusion and enabling quick resolution.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system allows dynamic adjustment of risk thresholds and access policies based on organizational needs and user contexts. By changing parameters such as risk score cutoff values or acceptable device contexts, the system can balance security threat mitigation with user convenience for different scenarios, enabling flexible policy adaptation without compromising either objective.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250193224A1Risk analysis based on device context
Publication Date: 2025.06.12 DELL PROD LP
  • US20250193224A1 patent drawing
  • US20250193224A1 patent drawing
  • US20250193224A1 patent drawing

AI summary

Techniques for analyzing risk based on device context are described. One example method includes authenticating a user for access to the computer system while the computer system is located at a particular location; in response to authenticating the user, capturing an image of an environment of the computer system at the particular location; generating a device context based on the captured image; determining a risk score based on the device context, wherein the risk score is associated with the computer system and the particular location and represents a determined risk of allowing the device to access a network while located at the particular location.