Distributed Network Access Control via Smart Contracts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized network access control systems are vulnerable to strategic failures and cyber-attacks, requiring costly redundancy and being susceptible to unauthorized access due to centralized policy decision and information points.
Innovation Solution
Distributing policy information points and policy decision points across multiple network endpoint nodes, utilizing smart contracts and consensus algorithms to determine access, and implementing a distributed ledger for secure and fault-tolerant network access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized NAC system is used, then policy decision and information points can be managed centrally, but the system becomes vulnerable to strategic failures and cyber-attacks requiring costly redundancy
Solution Approach 1:
The patent divides the centralized NAC system into distributed components by segmenting policy decision points and policy information points across multiple network endpoint nodes. Each node independently holds copies of policy decisions and information, eliminating single points of failure while reducing the need for complex centralized redundancy infrastructure.
2Object-affected harmful factors
If centralized policy decision point is used, then access control decisions can be made centrally, but the system is susceptible to unauthorized access due to centralized policy decision and information points
Solution Approach 1:
The patent segments the centralized policy decision point into multiple distributed policy decision points located at different network endpoint nodes. This distribution eliminates the single centralized decision point that could be compromised, as attackers would need to breach multiple independent nodes simultaneously to gain unauthorized access.
Solution Approach 2:
The patent implements copying of policy decisions and policy information points across multiple network endpoint nodes. Each node maintains local copies of the same policy data, ensuring that if one node is compromised, other nodes still have valid copies of the policies to continue providing secure access control.
3Reliability
If centralized NAC system with redundancy is implemented, then fault tolerance is improved, but the total cost of ownership increases due to expensive centralized equipment
Solution Approach 1:
The patent uses copying of policy decisions and information across existing network endpoint nodes rather than deploying expensive dedicated redundancy hardware. The system leverages copies already present in the network infrastructure to provide fault tolerance, eliminating the need for costly backup servers and redundancy equipment.
Solution Approach 2:
The patent makes existing network endpoint nodes serve multiple functions: they act as both regular network devices and as policy decision points/information points for NAC. This multi-functionality eliminates the need for separate dedicated NAC hardware, reducing the total cost of ownership while maintaining fault tolerance capabilities.
Data Source
AI summary
Various embodiments of network access control (NAC) systems and methods are provided herein to control access to a network comprising a plurality of network endpoint nodes, where each network endpoint node includes a policy information point and a policy decision point. The policy information point within each network endpoint node stores a distributed ledger including one or more client policies that must be satisfied to access the network, and a smart contract including a set of predefined rules defining network access behaviors and actions. Upon receiving a network access request from a client device outside of the network, the policy decision point within each network endpoint node executes the smart contract to determine whether the client device should be granted access, denied access or have restricted access to the network, and executes consensus algorithm to select one of the network endpoint nodes to be a policy decision point leader.


