Portable Hardware Authentication Client for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-based VPN solutions are limited by their operating system dependency, requiring separate installations on each client device and inability to support certain devices like VoIP phones, while hardware-based VPN gateways are non-portable and lack device identity solutions.

Innovation Solution

A portable, hardware-based authentication client device that maintains a list of pre-authorized client devices, supports multiple authentication methods, and pairs with a firewall or VPN appliance to enforce user-to-site network access control, allowing concurrent secure connections for multiple devices and providing an additional security layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If software-based VPN solutions are used, then ease of installation and deployment cost are improved, but device compatibility and security control are worsened

Engineering Contradiction:
Improvedeployment costVSAvoiddevice compatibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces a hardware authentication client as an intermediary device between the client device and the VPN gateway. This intermediary handles authentication and tunnel establishment, allowing software-based VPN solutions to work across diverse devices without requiring OS-specific agents on each client device, thereby improving device compatibility while maintaining ease of deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the VPN functionality into separate components: the hardware authentication client handles authentication and device identification, while the VPN gateway handles connection management. This segmentation allows the authentication client to be a portable hardware device that can serve multiple client devices, improving versatility without increasing deployment complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If hardware-based VPN gateways are used, then device compatibility and security control are improved, but portability and ease of operation are worsened

Engineering Contradiction:
Improvedevice compatibilityVSAvoidportability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The hardware authentication client serves as a portable intermediary that brings hardware-based authentication capabilities to users. Instead of requiring users to operate complex hardware VPN gateways, the authentication client is a simple portable device that automatically handles authentication, making hardware-based security portable and easy to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hardware authentication client performs authentication and device verification automatically without requiring user intervention or IT professional operation. The device self-manages the authentication process with the VPN gateway, making the system easy to operate while maintaining hardware-based security controls.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If software-based VPN solutions are used, then deployment cost is improved, but security control and device authorization are worsened

Engineering Contradiction:
Improvedeployment costVSAvoidsecurity control
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The hardware authentication client acts as a security intermediary that enforces device authorization policies before allowing VPN connections. It verifies device identities against authorized device lists and controls which devices can access the network, providing reliable security control while maintaining the cost-effectiveness of software-based VPN infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary device authorization by maintaining lists of authorized devices and verifying device identities before establishing VPN connections. This preliminary security check ensures that only authorized devices can access the network, improving security control without adding significant deployment cost.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple client devices need VPN access, then user flexibility is improved, but device complexity and authentication overhead are worsened

Engineering Contradiction:
Improveuser flexibilityVSAvoidauthentication overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication functions into a single hardware authentication client. Instead of requiring separate authentication mechanisms for each client device, the authentication client consolidates device verification, user authentication, and VPN tunnel establishment into one device, reducing authentication overhead while supporting multiple client devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware authentication client is designed as a universal device that can authenticate multiple different client devices (laptops, smartphones, tablets, VoIP phones) using a single interface. This multi-functionality allows users to flexibly access VPN from various devices without increasing authentication complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20210306300A1Portable, hardware-based authentication client to enforce user-to-site network access control restrictions
Publication Date: 2021.09.30 FORTINET INC
  • US20210306300A1 patent drawing
  • US20210306300A1 patent drawing
  • US20210306300A1 patent drawing

AI summary

Systems and methods for a portable, hardware-based authentication client solution that enforces user-to-site network access control restrictions is provided. According to various embodiments of the present disclosure, the authentication client device maintains a list of pre-authorized client devices. The authentication client device is assigned to a particular user of an enterprise network and paired with a firewall appliance. A connection establishment request for establishing a connection with an enterprise network via the firewall appliance is received by the authentication client device via a network interface. The authentication client device confirms the connection establishment request was initiated by the particular user by authenticating the particular user. When the particular user is successfully authenticated, it is verified whether the client device is on the list of pre-authorized client devices. When the verification is affirmative, a connection is established between the authentication client device and the firewall appliance.