Public Kiosk Scanning for Enterprise Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computers contaminated with malicious code can spread infections to other systems and networks without detection, causing significant damage before remedial measures can be taken.

Innovation Solution

A kiosk system is established in public places to scan visiting computers for malicious code before allowing access to an enterprise network, performing antivirus scans, security patch analyses, and security practice assessments to restrict access and prevent contamination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If periodic virus scans are performed to detect and clean malicious code, then network security is restored and protected, but damage has already occurred before detection

Engineering Contradiction:
Improvenetwork securityVSAvoidtime for damage occurrence
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary security verification by scanning computers for malicious code before they are allowed to access the enterprise network. The kiosk system performs antivirus scans, security patch analyses, and security practice assessments as a preliminary check, preventing contaminated computers from entering the network in the first place, thus eliminating the time loss associated with post-infection detection and remediation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive security verification tests are performed on visiting computers, then malicious code detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvemalicious code detection accuracyVSAvoidsecurity verification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive security verification process into three distinct functional modules: (1) antivirus scan module for detecting malicious code, (2) security patch analysis module for verifying software updates, and (3) security practice assessment module for evaluating security configurations. This segmentation allows each module to specialize in its specific detection task, improving overall detection accuracy while making the system more manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a kiosk system as an intermediary device between visiting computers and the enterprise network. The kiosk acts as a mediator that performs all comprehensive security verification tests, isolating the complexity of multiple security checks from the core network system. This intermediary approach enables thorough security scanning without directly complicating the enterprise network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control is granted based on security verification results, then network protection from contamination is improved, but access convenience for visitors deteriorates

Engineering Contradiction:
Improvenetwork protectionVSAvoidvisitor access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service security verification system where visiting computers automatically undergo scanning and assessment when they approach the enterprise network through the kiosk. The system autonomously performs antivirus scans, security patch analyses, and security practice assessments without requiring manual intervention from visitors or security personnel. Computers that pass verification are automatically granted access, while those that fail are denied access, eliminating the need for manual security checks and maintaining both network protection and visitor convenience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8146072B2System and method for updating software on a computer
Publication Date: 2012.03.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8146072B2 patent drawing
  • US8146072B2 patent drawing
  • US8146072B2 patent drawing

AI summary

One aspect of the invention is a method for updating the version of software resident on a computer that includes providing a kiosk in a public place. A communication path is established between the kiosk and a computer to be tested. It is determined, using the kiosk, whether at least one program resident on the computer is a preferred version.