Public Kiosk Scanning for Enterprise Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers contaminated with malicious code can spread infections to other systems and networks without detection, causing significant damage before remedial measures can be taken.
Innovation Solution
A kiosk system is established in public places to scan visiting computers for malicious code before allowing access to an enterprise network, performing antivirus scans, security patch analyses, and security practice assessments to restrict access and prevent contamination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If periodic virus scans are performed to detect and clean malicious code, then network security is restored and protected, but damage has already occurred before detection
Solution Approach 1:
The patent implements preliminary security verification by scanning computers for malicious code before they are allowed to access the enterprise network. The kiosk system performs antivirus scans, security patch analyses, and security practice assessments as a preliminary check, preventing contaminated computers from entering the network in the first place, thus eliminating the time loss associated with post-infection detection and remediation.
2Measurement precision
If comprehensive security verification tests are performed on visiting computers, then malicious code detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the comprehensive security verification process into three distinct functional modules: (1) antivirus scan module for detecting malicious code, (2) security patch analysis module for verifying software updates, and (3) security practice assessment module for evaluating security configurations. This segmentation allows each module to specialize in its specific detection task, improving overall detection accuracy while making the system more manageable and maintainable.
Solution Approach 2:
The patent introduces a kiosk system as an intermediary device between visiting computers and the enterprise network. The kiosk acts as a mediator that performs all comprehensive security verification tests, isolating the complexity of multiple security checks from the core network system. This intermediary approach enables thorough security scanning without directly complicating the enterprise network infrastructure.
3Reliability
If access control is granted based on security verification results, then network protection from contamination is improved, but access convenience for visitors deteriorates
Solution Approach 1:
The patent implements a self-service security verification system where visiting computers automatically undergo scanning and assessment when they approach the enterprise network through the kiosk. The system autonomously performs antivirus scans, security patch analyses, and security practice assessments without requiring manual intervention from visitors or security personnel. Computers that pass verification are automatically granted access, while those that fail are denied access, eliminating the need for manual security checks and maintaining both network protection and visitor convenience.
Data Source
AI summary
One aspect of the invention is a method for updating the version of software resident on a computer that includes providing a kiosk in a public place. A communication path is established between the kiosk and a computer to be tested. It is determined, using the kiosk, whether at least one program resident on the computer is a preferred version.


