Endpoint Health-Based Access Control for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Endpoint devices in computer networks often become misconfigured due to user lack of technical experience, leading to the spread of malicious software that can compromise network security, with conventional security software only quarantining affected devices without effectively preventing network access.

Innovation Solution

A system that generates fine-grain access control information based on user identity and endpoint health information, including the presence of malicious software, configuration validity, and installed countermeasures, to control access to network resources, using a controller and protection devices to apply user-specific, health-specific, and resource-specific access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security software quarantines endpoint devices with malicious software, then network security is protected, but network access is completely blocked even for devices that could safely connect

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing fine-grained access control that differentiates between various endpoint devices based on their individual health indicators. Instead of uniformly blocking all potentially infected devices, the system evaluates each device's specific security state (malware presence, patch level, configuration) and grants or denies access to specific network resources accordingly. This allows clean devices to maintain full access while potentially compromised devices receive restricted access only to resources necessary for remediation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamic access control where network permissions are not static but continuously adjusted based on real-time health indicator assessments. As endpoint devices undergo security remediation and improve their health status, their network access rights are dynamically updated. This dynamic approach allows the system to adapt access levels as devices transition from compromised to secure states, rather than maintaining permanent quarantine status.

Inventive Principle:
Principle #15Dynamics

2Reliability

If fine-grained access control is implemented based on user identity and endpoint health, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct functional components: health indicator collection modules that gather security state data, assessment engines that evaluate risks based on collected indicators, and access control enforcement points that implement decisions. This segmentation allows each component to specialize in specific tasks, making the overall complex system more manageable and maintainable while enabling sophisticated security decisions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary access control mechanism positioned between endpoint devices and network resources. This intermediary layer assesses health indicators and mediates access requests without requiring direct integration between endpoint devices and all network resources. The intermediary simplifies the architecture by centralizing the complex assessment logic and providing a standardized interface for access decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive health indicators are collected and assessed, then access control decisions are more accurate, but processing time and resource consumption increase

Engineering Contradiction:
Improvesecurity state assessmentVSAvoidaccess decision time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and pre-assessing health indicators before actual network access decisions are required. Endpoint devices undergo initial security assessments and have their health status pre-determined, allowing rapid access decisions to be made later without performing complete reassessments. This preliminary evaluation reduces the time required for real-time access control decisions while maintaining accurate security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial assessment action by focusing health indicator evaluation on the most critical security parameters relevant to specific network resources. Rather than performing exhaustive assessments of all possible security indicators for every access request, the system selectively evaluates the subset of indicators most pertinent to the requested resource type, reducing processing overhead while maintaining sufficient assessment accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8001610B1Network defense system utilizing endpoint health indicators and user identity
Publication Date: 2011.08.16 PULSE SECURE LLC
  • US8001610B1 patent drawing
  • US8001610B1 patent drawing
  • US8001610B1 patent drawing

AI summary

An endpoint defense system uses endpoint health indicators and user identity information to provide fine-grain access control over network resources. For example, the endpoint defense system may include a controller, a set of protection devices, and a set of agents. The agents are software applications installed on a set of endpoints to gather the health information that represents security states of the endpoint devices. The agents send updated health information to the controller. In response to a login attempt, the controller processes the health indicators and identity information through a set of administrator-defined policies to generate a set of access rights. The controller transfers the set of access rights to the protection devices. The protection devices then control user access to network resources according to the set of access rights. The controller sends updated sets of access rights to the protection devices whenever the access rights change.