Dynamic Network Access Control via Periodic Client Compliance Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems fail to monitor client devices for compliance with security rules after initial access is granted, leaving networks vulnerable to attacks and unauthorized changes.

Innovation Solution

Implementing a system where a network device periodically scans client devices during a communication session to identify hardware or software status and reports any non-compliance to the server, allowing dynamic modification of access rights to prevent security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication procedures are used to limit access to authorized users, then network security is improved, but no further security monitoring is performed after access is granted, leaving the network vulnerable to undetected client device changes and attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity monitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing security baselines during authentication and pre-configuring monitoring parameters before the client accesses network resources. This allows the system to proactively detect deviations from authorized configurations without requiring complex real-time analysis of all possible security states.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention implements continuous feedback mechanisms where the server receives periodic status information from the client device about its security configuration state. This feedback loop enables the system to detect when the client deviates from its authorized configuration and dynamically adjust access permissions accordingly, maintaining security without requiring overly complex monitoring infrastructure.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If continuous monitoring of client devices is implemented during communication sessions, then detection of security non-compliance is improved, but system resource consumption and monitoring complexity increase

Engineering Contradiction:
Improvesecurity compliance detectionVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Instead of continuous monitoring, the system employs periodic action by requesting status information from client devices at specific intervals or trigger events during the communication session. This approach maintains adequate security compliance detection while significantly reducing system resource consumption compared to continuous real-time monitoring of all client activities.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial monitoring by focusing only on specific security-relevant parameters and configuration elements rather than monitoring all client device activities. This selective approach achieves sufficient security compliance detection with reduced computational overhead and resource usage.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If access permissions are dynamically modified based on security status, then network security is enhanced, but access management complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamics by making access permissions flexible and adaptable rather than static. Access rights are automatically adjusted based on the client's current security compliance status, allowing the system to enhance security when needed while maintaining ease of operation through automated decision-making rather than manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention applies self-service by enabling the access management system to automatically modify permissions based on received security status information without requiring manual administrative intervention. The server autonomously evaluates compliance data and adjusts access accordingly, simplifying operations while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8601102B1Dynamic access management for network security
Publication Date: 2013.12.03 PULSE SECURE LLC
  • US8601102B1 patent drawing
  • US8601102B1 patent drawing
  • US8601102B1 patent drawing

AI summary

A method for managing access to network resources by a first network device may include establishing a communication session with the first network device. The method may also include receiving information from the first network device during the communication session, the information indicating that the first network device is not in compliance with at least one security-related rule. The method may further include determining whether to modify access by the first network device to at least one of the network resources based on the received information.