Distributed Security Policy Agents for Multi-AP Network Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Securing communication in computer networks with multiple access points is challenging as devices can bypass the main gateway, compromising network security by utilizing other access points, which existing centralized security software cannot effectively manage.
Innovation Solution
A method and system that utilize multiple security policy agents installed on each access point to enforce a common security policy across the network, ensuring secure communication by mapping and synchronizing security rules across all access points, allowing devices to roam freely while maintaining consistent security protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized security software is used on the main gateway, then security management is simplified, but security coverage is reduced as devices can bypass the main gateway through other access points
Solution Approach 1:
The patent divides the centralized security function into distributed security policy agents deployed on each access point. Each agent independently enforces security policies locally, eliminating the single point of control and ensuring that security coverage is maintained regardless of which access point a device connects to.
Solution Approach 2:
The patent implements local security enforcement by deploying security policy agents directly on each access point. This allows each access point to independently validate and enforce security policies for connected devices, ensuring consistent security coverage across the entire network without requiring centralized control.
2Area of stationary object
If multiple access points are deployed to increase signal coverage, then network coverage is improved, but security management complexity increases as each access point must be secured
Solution Approach 1:
The patent creates a universal security policy that can be applied across all access points. The security policy agent on each access point enforces the same comprehensive security rules, allowing the system to scale to multiple access points without proportionally increasing management complexity.
Solution Approach 2:
The patent replicates the security policy agent on each access point, creating identical copies of the security enforcement mechanism. This allows consistent security management across multiple access points while distributing the enforcement function, reducing the complexity of managing security on each individual device.
3Ease of operation
If security inspection is centralized on the main gateway, then security policy enforcement is simplified, but processing load on the gateway increases and may create bottlenecks
Solution Approach 1:
The patent segments the security inspection function from the main gateway and distributes it to security policy agents on each access point. This divides the processing load across multiple devices, preventing bottlenecks at the gateway while maintaining consistent security policy enforcement throughout the network.
4Adaptability or versatility
If devices are allowed to roam between access points freely, then network flexibility is improved, but security consistency may be compromised as different access points may have different security policies
Solution Approach 1:
The patent creates equipotential security conditions across all access points by deploying identical security policy agents that enforce the same security rules. This ensures that devices experience consistent security enforcement regardless of which access point they connect to, maintaining security consistency while allowing free roaming.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Systems and methods for managing communication of a plurality of devices in a computer network having a plurality of access points, including identifying, by a second access point of the computer network, a communication request from at least one device of the plurality of devices; sending, by a first access point of the computer network, at least one communication rule to the second access point, the at least one communication rule including conditions for communication corresponding to the identified communication request; and blocking, by the second access point, communication to the second access point when the received communication request is inadmissible according to the at least one communication rule.