Gateway Data Flow Identification for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control systems face limitations in accurately controlling network access without additional procedures in universal IP communication environments, particularly when IP specifications are not implemented, leading to implicit trust in data packets by the operating system and inability to control the network layer (OSI layer 3) by communication applications.

Innovation Solution

A system and method that includes a gateway with a processor configured to receive data packets, identify authorized data flows, inspect authentication information, and generate data flow identification information for the application processing layer, enabling precise control and processing of data packets based on authentication, thereby bypassing the need for tunneling and explicit IP specification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunneling generation is added to control data flow of authenticated targets, then network access control accuracy is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork access control accuracyVSAvoidadditional procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway performs authentication and generates data flow identification information in advance before actual data transmission. This preliminary action establishes authorized communication targets and creates identification markers that enable subsequent direct data flow control without requiring additional tunneling procedures during actual communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway acts as an intermediary between the application layer and network layer, inserting authentication information and generating data flow identification markers that bridge the gap between application-level authentication and network-level data packet routing, eliminating the need for complex tunneling mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If IP specification implementation is required for each communication, then network layer control precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork layer control precisionVSAvoidcommunication operation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent extracts authentication information from the complex IP specification implementation and separates it into independent data flow identification markers. This allows the application layer to control network communication using simple identification information without requiring detailed IP specification knowledge or manual configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway automatically generates data flow identification information and performs authentication based on pre-established authorized targets. This self-service mechanism eliminates the need for manual IP specification configuration by each application, as the gateway autonomously manages network layer control based on application-layer authentication results.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If applications trust data packets implicitly from the operating system, then ease of operation is maintained, but security deteriorates

Engineering Contradiction:
Improvedata packet processing simplicityVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The gateway performs preliminary authentication and generates data flow identification information before data packets are transmitted. Applications receive pre-authenticated data packets with embedded identification markers, allowing them to maintain simple processing operations while ensuring security through advance verification by the gateway.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway serves as a security intermediary that inserts authentication information into data packets at the network layer. This allows applications to continue trusting data packets from the operating system while the gateway subtly enhances security by embedding verification markers without disrupting application-level trust relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240348540A1System for controlling data flow based on logical connection identification and method thereof
Publication Date: 2024.10.17 PRIBIT TECH INC
  • US20240348540A1 patent drawing
  • US20240348540A1 patent drawing
  • US20240348540A1 patent drawing

AI summary

Disclosed is a gateway which includes a communication circuit, a memory, and a processor operatively connected with the communication circuit and the memory. The processor receives a data packet of a node through a network processing layer, identifies whether there is data flow corresponding to the data packet of the node and authorized from an external server, inspects authentication information of the data packet, when there is a need to inspect the authentication information of the data packet based on authentication information included in the data flow, generates data flow identification information capable of being identified by an application processing layer based on the data packet and forward the data packet to the application processing layer, and processes the forwarded data packet based on the data flow identification information by means of the application processing layer.