Port-Based LAN Access Control With Safety-Mode Tags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network access control methods are ineffective in preventing malicious activity within a network when authorized electronic devices breach security policies, as re-issuing digital certificates can be resource-intensive and time-consuming, allowing unauthorized access and potential damage.
Innovation Solution
Implementing a system that assigns an authorization tag to digital certificates, enabling a safety mode tag to restrict access to a limited scope of actions for compromised devices, and monitoring device parameters to detect breaches, using internal and external device monitoring managers to ensure accurate breach detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-issuing digital certificates is performed when a device breaches security policy, then network security is improved, but system resource consumption and time required increase significantly
Solution Approach 1:
The patent applies preliminary action by continuously monitoring device compliance status before breaches occur. The system proactively detects policy violations (such as unauthorized software installation or antivirus deactivation) and triggers automated response actions including temporary access revocation and alerting security administrators, rather than waiting for breach detection and then initiating slow certificate re-issuing processes.
Solution Approach 2:
The patent extracts the critical security function from the slow certificate re-issuing process. Instead of relying solely on re-issuing certificates to respond to breaches, the system separates and implements immediate access control actions (such as revoking network access) that can be executed instantly, while certificate re-issuing is performed as a separate, less time-critical background operation.
2Reliability
If re-issuing digital certificates is performed when a device breaches security policy, then network security is improved, but processing time and resource consumption increase
Solution Approach 1:
The system performs preliminary compliance monitoring and detection actions continuously, identifying security breaches before they propagate. This allows the system to take immediate corrective actions (access revocation, alerts) without waiting for the lengthy certificate re-issuing process, thereby maintaining security productivity.
Solution Approach 2:
The patent extracts the immediate security response function from the certificate re-issuing process. By implementing separate access control mechanisms that can revoke network access instantly, the system maintains high processing efficiency for security responses while certificate re-issuing operates as a separate, optimized background task.
3Measurement precision
If continuous monitoring of device parameters is implemented, then breach detection accuracy is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent applies local quality by monitoring only specific, critical device parameters and compliance indicators relevant to network security policies (such as antivirus status, unauthorized software installation, system configuration changes) rather than implementing comprehensive monitoring of all device attributes. This targeted approach maintains high breach detection accuracy for security-relevant events while minimizing system complexity.
Solution Approach 2:
The monitoring system is designed with multi-functionality, serving multiple purposes: it monitors compliance status, detects breaches, triggers security responses, and provides audit logging. This universal monitoring framework reduces overall system complexity by consolidating functions into a single integrated solution rather than requiring separate specialized systems.
Data Source
AI summary
A method and a server for port-based network access control of a plurality of host network devices in a local area network (LAN) are provided. The method comprises: generating, for a given host network device, a respective network certificate for accessing the LAN; generating, for the respective network certificate associated with the given host network device, a respective authorization tag, indicative of a scope of actions that the given host network device is authorized to execute in the LAN; and transmitting data indicative of an association between the respective network certificate and the respective authorization tag associated with the given host network device to the authentication server of the LAN, thereby causing the authentication server to enable the given host network device to: (i) access the LAN and (ii) execute the scope of actions therein.


