Location-Based Network Access Control System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access systems require manual configuration of security protocols and parameters, making it difficult for users to establish secure connections, and there is a need for automated, robust, and location-based access control to prevent unauthorized access.

Innovation Solution

A system comprising a client device, network access device, locationing server, and security server that automatically determines network access based on geographical location and security protocols, using state machines and authentication methods like IEEE 802.1X, MAC, and WEP to grant or deny access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security protocols and parameters is required, then network security control is maintained, but user ability to establish connections deteriorates

Engineering Contradiction:
Improvenetwork security controlVSAvoiduser ability to establish connections
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service through automatic location-based access control. The network access device automatically determines whether to grant access based on the client device's geographical location without requiring manual user configuration of security protocols. The system serves itself by autonomously making access decisions based on pre-configured location policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring acceptable geographical locations and access policies before actual network connection attempts. The network administrator sets up location-based access rules in advance, so that when a connection request occurs, the system can immediately determine access eligibility based on pre-established criteria rather than requiring real-time manual configuration.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If users are given capability to establish connections, then ease of connection is improved, but network security integrity deteriorates

Engineering Contradiction:
Improveease of connectionVSAvoidnetwork security integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary mechanism - the location determination and evaluation system - that stands between the user's connection request and the network access decision. This intermediary automatically evaluates whether the client device's location satisfies pre-configured access criteria, providing automated security enforcement without requiring users to manually configure security settings or understand security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system performs self-service by autonomously monitoring and controlling network access based on location data. The network access device automatically determines whether to permit or deny connections based on the client device's geographical location compared against pre-configured acceptable locations, eliminating the need for manual security interventions while maintaining security integrity.

Inventive Principle:
Principle #25Self-service

3Reliability

If automated location-based access control is implemented, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the access control function into distinct modular components: a location determination module that obtains geographical location data, a location evaluation module that compares location against pre-configured criteria, and an access decision module that permits or denies connections. This segmentation allows each component to perform its specific function independently, making the overall system more manageable and maintainable despite the added automation capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9112879B2Location determined network access
Publication Date: 2015.08.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9112879B2 patent drawing
  • US9112879B2 patent drawing
  • US9112879B2 patent drawing

AI summary

A system and method for network authentication is provided. A network access device is operable to establish a communications with an internal network. A client device is operable to request and establish the communications over the internal network by interfacing with the network access device. A processor is operable to interface with the network access device to establish the communications between the client device and the internal network. The processor is also operable to establish a communications level for the communications based on the location of the client device.