Dynamic Network Access Control for Portable End Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security methods based on port segmentation and access lists are insufficient for modern, portable end nodes, as they fail to effectively manage the increased risk of unauthorized access and malicious software propagation, due to compatibility issues between proprietary NAC solutions and varying end node, network, and security data configurations.

Innovation Solution

A method that identifies attributes of end nodes and network devices to select an appropriate network access control (NAC) implementation, combining authentication and posture checking methods, and dynamically applies the selected NAC implementation to ensure secure network access by utilizing a handler process that can interoperate with diverse network components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional port segmentation and access lists are used for network security, then network access control is provided, but the system cannot effectively manage unauthorized access and malicious software propagation due to incompatibility with modern portable end nodes

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidcompatibility with portable end nodes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network access control that adapts to different end node types and network conditions. The system dynamically selects between multiple NAC implementations (802.1x, MAC authentication, web authentication) based on real-time assessment of end node capabilities and network state, rather than using static port segmentation rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters by selecting different authentication methods and control implementations based on detected end node attributes. When portable end nodes are detected, the system transitions from traditional access lists to alternative authentication mechanisms that are compatible with modern devices.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If proprietary NAC solutions are deployed for each component (end node, network device, security data), then specific security functions are provided, but interoperability between components fails due to vendor-specific implementations

Engineering Contradiction:
Improvesecurity function effectivenessVSAvoidinteroperability between components
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal NAC framework that can work with multiple vendor implementations. The system assesses available functions across different components and selects combinations that provide effective security regardless of vendor-specific capabilities, making the solution interoperable across heterogeneous network environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The NAC implementation selector acts as an intermediary layer between proprietary components. It assesses the capabilities of end nodes, network devices, and security data stores, then coordinates their interaction to achieve effective security control despite vendor-specific implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple NAC implementations are available to handle different scenarios, then security coverage is improved, but system complexity increases making selection and management difficult

Engineering Contradiction:
Improvesecurity coverage across scenariosVSAvoidNAC implementation selection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated assessment and selection of NAC implementations. The NAC selector automatically evaluates end node attributes, network device capabilities, and security data availability, then selects the appropriate authentication method without requiring manual configuration or complex administrative decisions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary assessment of available NAC implementations and end node capabilities before access control decisions are made. By pre-evaluating which authentication methods are available and compatible, the system simplifies the actual access control execution phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8510803B2Dynamic network access control method and apparatus
Publication Date: 2013.08.13 TREND MICRO INC
  • US8510803B2 patent drawing
  • US8510803B2 patent drawing
  • US8510803B2 patent drawing

AI summary

A method of network access control identifies, in response to a request by an end node to access a network, attributes of the end node and of a device receiving the request. Based on the attributes, a network access control implementation is selected from a plurality of network access control implementations to apply to the request.