Federating Trust in Heterogeneous Networks via Security Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many network users' processing devices are vulnerable to security threats due to lack of or outdated security software, posing risks of identity theft and network disruptions.

Innovation Solution

A system that performs security checks on devices before network access, redirecting non-compliant devices to a portal offering options to update or purchase security products, ensuring compliance with security policies before granting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security checks are performed on all devices before network access, then network security is improved, but network access efficiency deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs security checks before granting network access, ensuring that devices meet security requirements in advance. This preliminary action prevents potentially harmful devices from accessing the network, thereby improving network security while maintaining access efficiency through pre-validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary security checking mechanism between the device and the network. This intermediary layer validates devices without requiring deep inspection of every device, balancing security requirements with access efficiency by filtering devices at the network boundary rather than requiring exhaustive checks of all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security software is required on user devices, then protection from malicious software is improved, but device compatibility deteriorates

Engineering Contradiction:
Improveprotection from malicious softwareVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements partial security checking by focusing on essential security features rather than requiring complete security software suites. This approach provides adequate protection from malicious software while reducing the burden on devices, thereby improving compatibility across different device types and security software configurations.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system adjusts security requirement parameters to accommodate different device types and security software versions. By making security requirements configurable and adaptable rather than fixed, the system maintains protection effectiveness while improving device compatibility across heterogeneous networks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7584503B1Federating trust in a heterogeneous network
Publication Date: 2009.09.01 PULSE SECURE LLC
  • US7584503B1 patent drawing
  • US7584503B1 patent drawing
  • US7584503B1 patent drawing

AI summary

A check of a processing device is performed. A device may receive a network access request to access a network from a first processing device. A security check may be caused to be performed on the first processing device. Whether to grant the network access request to the first processing device is based on a result of the security check.