Gateway Data Flow Identification for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control systems face limitations in accurately controlling network access without additional procedures in universal IP communication environments, particularly when IP specifications are not implemented, leading to implicit trust in data packets by the operating system and inability to control the network layer (OSI layer 3) by communication applications.
Innovation Solution
A system and method that includes a gateway with a processor configured to receive data packets, identify authorized data flows, inspect authentication information, and generate data flow identification information for the application processing layer, enabling precise control and processing of data packets based on authentication, thereby bypassing the need for tunneling and explicit IP specification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tunneling generation is added to control data flow of authenticated targets, then network access control accuracy is improved, but device complexity and processing overhead increase
Solution Approach 1:
The gateway performs authentication and generates data flow identification information in advance before actual data transmission. This preliminary action establishes authorized communication targets and creates identification markers that enable subsequent direct data flow control without requiring additional tunneling procedures during actual communication.
Solution Approach 2:
The gateway acts as an intermediary between the application layer and network layer, inserting authentication information and generating data flow identification markers that bridge the gap between application-level authentication and network-level data packet routing, eliminating the need for complex tunneling mechanisms.
2Measurement precision
If IP specification implementation is required for each communication, then network layer control precision is improved, but ease of operation deteriorates
Solution Approach 1:
The patent extracts authentication information from the complex IP specification implementation and separates it into independent data flow identification markers. This allows the application layer to control network communication using simple identification information without requiring detailed IP specification knowledge or manual configuration.
Solution Approach 2:
The gateway automatically generates data flow identification information and performs authentication based on pre-established authorized targets. This self-service mechanism eliminates the need for manual IP specification configuration by each application, as the gateway autonomously manages network layer control based on application-layer authentication results.
3Ease of operation
If applications trust data packets implicitly from the operating system, then ease of operation is maintained, but security deteriorates
Solution Approach 1:
The gateway performs preliminary authentication and generates data flow identification information before data packets are transmitted. Applications receive pre-authenticated data packets with embedded identification markers, allowing them to maintain simple processing operations while ensuring security through advance verification by the gateway.
Solution Approach 2:
The gateway serves as a security intermediary that inserts authentication information into data packets at the network layer. This allows applications to continue trusting data packets from the operating system while the gateway subtly enhances security by embedding verification markers without disrupting application-level trust relationships.
Data Source
AI summary
Disclosed is a gateway which includes a communication circuit, a memory, and a processor operatively connected with the communication circuit and the memory. The processor receives a data packet of a node through a network processing layer, identifies whether there is data flow corresponding to the data packet of the node and authorized from an external server, inspects authentication information of the data packet, when there is a need to inspect the authentication information of the data packet based on authentication information included in the data flow, generates data flow identification information capable of being identified by an application processing layer based on the data packet and forward the data packet to the application processing layer, and processes the forwarded data packet based on the data flow identification information by means of the application processing layer.


