Dynamic Security Authentication Proxy for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems lack dynamic and adaptive mechanisms to manage authentication and authorization processes efficiently, particularly in handling various types of network access points and resources, leading to potential security vulnerabilities and inefficient resource allocation.

Innovation Solution

A system and method for network access point authorization that incorporates a Dynamic Security Authentication Service Proxy server (DSASP) comprising an access policy module and a Dynamic Security Data and Policy Database (DSDPD), which processes authentication requests using RADIUS, DIAMETER, or other protocols, and enforces security policies based on real-time data from authentication servers and Network Security Monitoring Systems to determine authorization levels and restrict access as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static authentication systems are used, then system simplicity is maintained, but security vulnerabilities increase and adaptability to different network access points deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: authentication servers, authorization servers, policy decision servers, and network access servers. Each component performs a specific function, allowing the system to be more secure and adaptable while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from static authentication to dynamic authentication where security policies, authorization levels, and access rights are determined in real-time based on current system state, user credentials, and network conditions. This dynamic approach enhances security and adaptability without requiring complete system redesign.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If dynamic security policies are implemented, then adaptability to different network resources improves, but processing time and system complexity increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Security policies, authorization rules, and access control parameters are pre-configured and stored in databases before authentication requests arrive. When a user attempts to access network resources, the system quickly retrieves and applies pre-defined policies rather than creating them in real-time, significantly reducing processing time while maintaining high adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Policy decision servers act as intermediaries between authentication servers and network resources. These intermediaries cache policy information and handle policy evaluation, allowing the main authentication system to remain responsive while implementing complex dynamic security policies for different network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time authentication and authorization is performed, then security control is improved, but network resource consumption increases

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Different levels of authentication and authorization are applied to different network resources based on their security requirements. Critical resources receive rigorous real-time verification, while less sensitive resources use cached credentials or simplified verification processes. This localized approach maintains security control while reducing overall network resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system caches authentication results and authorization decisions for reuse. When users access multiple resources, previously verified credentials and granted authorizations are recovered and reused rather than re-verifying everything from scratch, significantly reducing repeated network resource consumption while maintaining security control.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS9027079B2Method and system for dynamic security using authentication servers
Publication Date: 2015.05.05 FORESCOUT TECHNOLOGIES INC
  • US9027079B2 patent drawing
  • US9027079B2 patent drawing
  • US9027079B2 patent drawing

AI summary

Disclosed is a method and system for network access control, including an authentication proxy that authenticates different access-points, retrieves data from security databases and from Network Monitoring Systems, processing said data according to a dynamic security policy and using said processing outcome to determine the access level which will be granted to an access point in the network.