Endpoint Health-Based Access Control for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Endpoint devices in computer networks often become misconfigured due to user lack of technical experience, leading to the spread of malicious software that can compromise network security, with conventional security software only quarantining affected devices without effectively preventing network access.
Innovation Solution
A system that generates fine-grain access control information based on user identity and endpoint health information, including the presence of malicious software, configuration validity, and installed countermeasures, to control access to network resources, using a controller and protection devices to apply user-specific, health-specific, and resource-specific access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security software quarantines endpoint devices with malicious software, then network security is protected, but network access is completely blocked even for devices that could safely connect
Solution Approach 1:
The patent applies local quality by implementing fine-grained access control that differentiates between various endpoint devices based on their individual health indicators. Instead of uniformly blocking all potentially infected devices, the system evaluates each device's specific security state (malware presence, patch level, configuration) and grants or denies access to specific network resources accordingly. This allows clean devices to maintain full access while potentially compromised devices receive restricted access only to resources necessary for remediation.
Solution Approach 2:
The system implements dynamic access control where network permissions are not static but continuously adjusted based on real-time health indicator assessments. As endpoint devices undergo security remediation and improve their health status, their network access rights are dynamically updated. This dynamic approach allows the system to adapt access levels as devices transition from compromised to secure states, rather than maintaining permanent quarantine status.
2Reliability
If fine-grained access control is implemented based on user identity and endpoint health, then network security is enhanced, but system complexity increases
Solution Approach 1:
The patent segments the access control system into distinct functional components: health indicator collection modules that gather security state data, assessment engines that evaluate risks based on collected indicators, and access control enforcement points that implement decisions. This segmentation allows each component to specialize in specific tasks, making the overall complex system more manageable and maintainable while enabling sophisticated security decisions.
Solution Approach 2:
The system introduces an intermediary access control mechanism positioned between endpoint devices and network resources. This intermediary layer assesses health indicators and mediates access requests without requiring direct integration between endpoint devices and all network resources. The intermediary simplifies the architecture by centralizing the complex assessment logic and providing a standardized interface for access decisions.
3Measurement precision
If comprehensive health indicators are collected and assessed, then access control decisions are more accurate, but processing time and resource consumption increase
Solution Approach 1:
The system performs preliminary actions by continuously collecting and pre-assessing health indicators before actual network access decisions are required. Endpoint devices undergo initial security assessments and have their health status pre-determined, allowing rapid access decisions to be made later without performing complete reassessments. This preliminary evaluation reduces the time required for real-time access control decisions while maintaining accurate security assessments.
Solution Approach 2:
The system applies partial assessment action by focusing health indicator evaluation on the most critical security parameters relevant to specific network resources. Rather than performing exhaustive assessments of all possible security indicators for every access request, the system selectively evaluates the subset of indicators most pertinent to the requested resource type, reducing processing overhead while maintaining sufficient assessment accuracy.
Data Source
AI summary
An endpoint defense system uses endpoint health indicators and user identity information to provide fine-grain access control over network resources. For example, the endpoint defense system may include a controller, a set of protection devices, and a set of agents. The agents are software applications installed on a set of endpoints to gather the health information that represents security states of the endpoint devices. The agents send updated health information to the controller. In response to a login attempt, the controller processes the health indicators and identity information through a set of administrator-defined policies to generate a set of access rights. The controller transfers the set of access rights to the protection devices. The protection devices then control user access to network resources according to the set of access rights. The controller sends updated sets of access rights to the protection devices whenever the access rights change.


