Controller-Based Network Access Control System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control methods, such as those using TCP/IP protocols, are vulnerable to unauthorized access and difficult to manage for multiple nodes, especially when terminals change IP addresses, leading to security vulnerabilities and inefficient control over data packet flow.
Innovation Solution
A system that includes nodes, servers, and gateways with access control applications to manage tunnel generation and static IP assignment, ensuring secure data packet forwarding by authenticating and authorizing nodes and users through a controller, which generates and manages tunnels based on predefined policies, and performs firewall functions to block unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARP spoofing is used to block unauthorized terminals, then network access control is improved, but network load increases
Solution Approach 1:
The patent introduces a gateway as an intermediary device between the terminal and the network. The gateway performs authentication and authorization functions, and assigns IP addresses dynamically. This mediator approach reduces the direct load on the network core by handling access control at the edge, improving both security and network efficiency.
Solution Approach 2:
The gateway is designed to perform multiple functions: authentication, authorization, IP address assignment, and traffic management. By consolidating these functions into a single device, the system avoids the need for multiple separate security mechanisms that would increase overall network load.
2Ease of operation
If dynamic IP assignment is used, then ease of operation is improved, but access control precision deteriorates
Solution Approach 1:
The system implements a feedback mechanism where the gateway continuously monitors terminal authentication status and IP address assignments. When a terminal is authenticated, the gateway assigns an IP address and maintains binding information. This feedback loop ensures that dynamic IP assignment remains secure and precise by continuously verifying terminal identity against authorized lists.
Solution Approach 2:
The system performs preliminary authentication before IP address assignment. Terminals must first be authenticated and authorized by the gateway before receiving an IP address. This preliminary action ensures that only authorized terminals receive network access, maintaining access control precision while still providing dynamic assignment to authenticated users.
3Ease of manufacture
If tunneling IP is randomly assigned by DHCP, then ease of manufacture is improved, but access control capability deteriorates
Solution Approach 1:
The patent changes the parameter of IP address assignment from random DHCP to controlled gateway assignment. The gateway assigns IP addresses based on authentication results and binding information, transforming the assignment mechanism from uncontrolled randomness to controlled precision. This maintains ease of configuration while significantly improving access control capability.
4Measurement precision
If static IP is assigned to each user and terminal, then access control precision is improved, but device complexity increases
Solution Approach 1:
The system transitions from static IP assignment to dynamic IP assignment managed by the gateway. IP addresses are assigned dynamically based on authentication results and binding information, eliminating the need for manual static configuration for each user and terminal. This dynamic approach maintains access control precision while significantly reducing management complexity.
Data Source
AI summary
A node according to an embodiment of the present disclosure includes a communication circuit, a processor operatively connected to the communication circuit, and a memory operatively connected to the processor and that stores a target application and an access control application, and the memory stores instructions that, when executed by the processor, cause the node to receive tunnel generation information necessary to generate a gateway and a tunnel from an external server, through the access control application, to request the gateway to generate the tunnel based on the tunnel generation information, through the access control application, to receive static IP information assigned to the node or each user of the node from the gateway, through the access control application, and to transmit the static IP information to the external server, through the access control application.


