Isolated Subnet Architecture for Network Security Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virus protection software is ineffective against new viruses as it relies on identifying known features, failing to detect newly created viruses, and does not adequately protect network systems from malicious applications exploiting security flaws in popular operating systems.

Innovation Solution

Implementing a network architecture with an isolated sub-network that directs non-conforming clients to access the latest security policies, using an address server to determine compliance and isolate clients until they meet the required security standards, thereby preventing access to the main network until they are updated with the latest security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virus protection software scans files for known virus features, then known viruses can be detected and removed, but new viruses created after the software was developed cannot be detected

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidability to detect new viruses
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by establishing security policies and client conformance requirements before viruses can exploit security flaws. The address server pre-configures security policies and automatically evaluates client compliance, updating policies proactively rather than reactively when new threats emerge.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary address server that acts as a mediator between clients and the network. This server enforces security policies by evaluating client conformance and directing non-compliant clients to an isolated sub-network, preventing potential virus transmission without requiring traditional signature-based detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an isolated sub-network is implemented to enforce security policies on non-conforming clients, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into two distinct parts: the main network and an isolated sub-network. This segmentation allows non-conforming clients to be automatically directed to the isolated sub-network where they can update their security configurations, while conforming clients access the main network. The address server implements this segmentation through IP address assignment and client redirection mechanisms.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If traditional virus protection software is used, then known viruses can be removed, but the system remains vulnerable to new malicious applications exploiting security flaws

Engineering Contradiction:
Improvesimplicity of virus protectionVSAvoidprotection against new threats
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

Instead of trying to detect and remove viruses after they infiltrate the system, the patent inverts the approach by preventing non-conforming clients from accessing the network in the first place. The address server evaluates client conformance to security policies before granting network access, blocking potential threats proactively rather than reacting to them after infection occurs.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7877786B2Method, apparatus and network architecture for enforcing security policies using an isolated subnet
Publication Date: 2011.01.25 NOKIA OF AMERICA CORP
  • US7877786B2 patent drawing
  • US7877786B2 patent drawing
  • US7877786B2 patent drawing

AI summary

A method for enforcing security policies required to gain access to a network includes determining if a client desiring a connection to the network is in conformance with a current version of the security policies, and if a client is not in conformance with a current version of the security policies, denying the client access to the network and directing the client to an isolated sub-network for accessing a current version of the security policies. In one embodiment of the present invention an address server isolates non-conforming clients from the network and the network resources by directing non-conforming clients to an isolated sub-network. The isolated sub-network further directs the non-conforming clients to, for example, a local server or web-site for accessing a current version of the security policies.