Distributed Network Access Control via Smart Contracts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized network access control systems are vulnerable to strategic failures and cyber-attacks, requiring costly redundancy and being susceptible to unauthorized access due to centralized policy decision and information points.

Innovation Solution

Distributing policy information points and policy decision points across multiple network endpoint nodes, utilizing smart contracts and consensus algorithms to determine access, and implementing a distributed ledger for secure and fault-tolerant network access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized NAC system is used, then policy decision and information points can be managed centrally, but the system becomes vulnerable to strategic failures and cyber-attacks requiring costly redundancy

Engineering Contradiction:
Improvefault toleranceVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized NAC system into distributed components by segmenting policy decision points and policy information points across multiple network endpoint nodes. Each node independently holds copies of policy decisions and information, eliminating single points of failure while reducing the need for complex centralized redundancy infrastructure.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If centralized policy decision point is used, then access control decisions can be made centrally, but the system is susceptible to unauthorized access due to centralized policy decision and information points

Engineering Contradiction:
Improvecyber-attacksVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the centralized policy decision point into multiple distributed policy decision points located at different network endpoint nodes. This distribution eliminates the single centralized decision point that could be compromised, as attackers would need to breach multiple independent nodes simultaneously to gain unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements copying of policy decisions and policy information points across multiple network endpoint nodes. Each node maintains local copies of the same policy data, ensuring that if one node is compromised, other nodes still have valid copies of the policies to continue providing secure access control.

Inventive Principle:
Principle #26Copying

3Reliability

If centralized NAC system with redundancy is implemented, then fault tolerance is improved, but the total cost of ownership increases due to expensive centralized equipment

Engineering Contradiction:
Improvefault toleranceVSAvoidcost of ownership
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses copying of policy decisions and information across existing network endpoint nodes rather than deploying expensive dedicated redundancy hardware. The system leverages copies already present in the network infrastructure to provide fault tolerance, eliminating the need for costly backup servers and redundancy equipment.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent makes existing network endpoint nodes serve multiple functions: they act as both regular network devices and as policy decision points/information points for NAC. This multi-functionality eliminates the need for separate dedicated NAC hardware, reducing the total cost of ownership while maintaining fault tolerance capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11496518B2System and method for distributed network access control
Publication Date: 2022.11.08 DELL PROD LP
  • US11496518B2 patent drawing
  • US11496518B2 patent drawing
  • US11496518B2 patent drawing

AI summary

Various embodiments of network access control (NAC) systems and methods are provided herein to control access to a network comprising a plurality of network endpoint nodes, where each network endpoint node includes a policy information point and a policy decision point. The policy information point within each network endpoint node stores a distributed ledger including one or more client policies that must be satisfied to access the network, and a smart contract including a set of predefined rules defining network access behaviors and actions. Upon receiving a network access request from a client device outside of the network, the policy decision point within each network endpoint node executes the smart contract to determine whether the client device should be granted access, denied access or have restricted access to the network, and executes consensus algorithm to select one of the network endpoint nodes to be a policy decision point leader.