Network Access Control Certificate of Health Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control methods are processor-intensive and not scalable for devices with stringent constraints on processor speed, memory, and communications bandwidth, such as mobile phones, which face challenges in maintaining compliance with security policies due to their diverse configurations.
Innovation Solution
Implementing a certificate of health or trusted token on client devices to verify integrity, allowing access to the network based on a valid certificate rather than exchanging complete integrity measurements, and initiating a remediation process when the certificate is invalid to update the device to compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete integrity measurements are exchanged between client device and server, then network access control accuracy is improved, but processor load and communication bandwidth consumption increase
Solution Approach 1:
The patent extracts only the essential integrity verification information needed for access control decisions, rather than exchanging complete integrity measurements. The server sends a subset of integrity measurements focused on critical security attributes, reducing the data volume while maintaining access control accuracy.
Solution Approach 2:
The patent implements partial action by exchanging only the necessary portion of integrity measurements required for access control verification. Instead of complete measurement exchange, the system transmits a targeted subset that provides sufficient information for accurate access decisions, reducing processor load and bandwidth consumption.
2Reliability
If complete integrity measurements are exchanged between client device and server, then network access control accuracy is improved, but communication bandwidth consumption increases
Solution Approach 1:
The system extracts and transmits only the critical integrity measurement data necessary for access control verification, rather than exchanging complete integrity measurement sets. This extraction approach maintains control accuracy while significantly reducing communication bandwidth requirements.
Solution Approach 2:
The patent applies partial action by transmitting a partial set of integrity measurements that are sufficient for access control decisions. This reduces the quantity of data exchanged over the network while preserving the essential verification functionality.
3Reliability
If traditional network access control methods are used, then security policy compliance is ensured, but device complexity and processor requirements increase
Solution Approach 1:
The patent extracts only the essential security verification elements needed for policy compliance checking, reducing the complexity of the access control implementation on client devices while maintaining security assurance.
Solution Approach 2:
The system implements partial verification by checking a subset of integrity measurements against security policies, rather than performing complete verification. This reduces device complexity and processor requirements while ensuring security policy compliance through targeted checks.
Data Source
AI summary
A method, apparatus, and electronic device for conforming integrity of a client device 106 are disclosed. A memory 1100 may store a policy tag 404 associated with a subgroup of a group of policies 1102 and having a tag timestamp. A network interface 1060 may receive the certificate of health 300 from the client device 106. A processor 1010 may extract from the certificate of health a certificate timestamp 302 and a policy tag 304. The processor 1010 may access the tag timestamp. The processor 1010 may execute a comparison of the certificate timestamp 302 with the tag timestamp. The network interface 1060 may grant access to a network 104 based in part upon the comparison.


