Network Access Control via DHCP Filtering and Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network health enforcement methods struggle to effectively restrict non-compliant client computers' access to a network until they meet administrator-defined health policy standards, lacking a systematic approach to guide clients in remediation and restrict access efficiently.

Innovation Solution

A method where clients send a Statement of Health (SoH) to a server, which determines compliance and sends remediation and filtering instructions via DHCP or DHCPv6, allowing clients to download necessary updates by restricting access to specific network portions until compliance is achieved, using firewall rules to manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DHCP is used to control client access by modifying routes and gateway, then network access control is improved, but the ability to provide systematic remediation guidance and restrict access to specific remediation resources is insufficient

Engineering Contradiction:
Improvenetwork access controlVSAvoidremediation guidance capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments network access into different levels: full network access for compliant clients and restricted access to specific remediation servers for non-compliant clients. The DHCP server divides the network into accessible and inaccessible segments based on compliance status, allowing clients to only reach remediation resources while blocking access to other network portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the DHCP server acts as a mediator between non-compliant clients and network resources. Instead of directly controlling all network access, the DHCP server provides filtered routing information that guides clients to appropriate remediation servers while blocking access to other resources, enabling systematic remediation guidance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If non-compliant clients are completely blocked from network access, then network security is improved, but clients cannot obtain necessary updates and patches to achieve compliance

Engineering Contradiction:
Improvenetwork security riskVSAvoidclient remediation capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies local quality by providing different network access permissions to different parts of the network based on client compliance status. Non-compliant clients receive restricted access quality that allows communication only with specific remediation servers, while compliant clients receive full network access quality. This localized access control enables security maintenance while preserving remediation capability.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If full network access is granted to all clients, then ease of operation is improved, but network health policy compliance cannot be enforced and network risk increases

Engineering Contradiction:
Improveclient network accessVSAvoidhealth policy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic network access control where client access permissions change based on their compliance status. Initially, non-compliant clients receive restricted access to remediation resources only. After applying updates and achieving compliance, clients dynamically transition to full network access. This dynamic adjustment balances ease of operation with health policy enforcement.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9225684B2Controlling network access
Publication Date: 2015.12.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9225684B2 patent drawing
  • US9225684B2 patent drawing
  • US9225684B2 patent drawing

AI summary

Systems and methods for controlling network access determine that a client computer on the network is in compliance with administrator-defined network health policy standards before the client computer is granted access to the network. A packet exchange mechanism is defined wherein filtering instructions from a server are converted into firewall rules on the client computer to restrict client access to remediation servers on the network. The client computer obtains update patches from the remediation servers to become compliant with network health policy standards.