MFA Network Access Rule Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication (MFA) methods are impractical for managing network access rules across large user bases, requiring constant IT professional intervention and not easily applicable to network layer access.

Innovation Solution

Implementing a method that uses MFA to automatically grant or override network access rules by presenting users with a multi-factor authentication process upon access requests, allowing network access only after successful authentication, and temporarily modifying security rules based on user confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MFA is implemented for network access control, then security is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to perform self-service authentication through MFA without requiring IT professional intervention. Users receive automated prompts on their devices to complete authentication challenges, and the system automatically modifies network access rules based on their responses, eliminating the need for manual configuration by IT staff.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (IT professionals manually configuring access rules) with automated electronic systems. The MFA mechanism automatically authenticates users, receives responses, and modifies network access rules through programmatic operations, substituting human manual work with automated digital processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual network access rule management is used, then security control is maintained, but productivity and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system transfers security control from IT professionals to end users. Users receive automated MFA challenges on their devices, respond with authentication codes, and the system automatically applies the appropriate network access rules. This self-service model eliminates the bottleneck of IT professional availability while maintaining security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The MFA-based system operates continuously without interruption to business operations. Unlike manual processes that require IT staff availability, the automated MFA system processes authentication requests 24/7, ensuring continuous network access management and eliminating productivity losses associated with manual rule configuration.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If MFA process is implemented automatically, then ease of operation is improved, but loss of time for authentication process increases

Engineering Contradiction:
Improveease of operationVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring MFA challenges and authentication flows before access is needed. Users have their authentication codes ready on their devices, and the system has pre-established the MFA challenge-response mechanism, so when access is required, the process executes quickly without time-consuming setup or manual intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11012433B2Method and system for modifying network connection access rules using multi-factor authentication (MFA)
Publication Date: 2021.05.18 ZERO NETWORKS LTD
  • US11012433B2 patent drawing
  • US11012433B2 patent drawing
  • US11012433B2 patent drawing

AI summary

A method and a system for modifying network connection access rules using multi factor authentication (MFA) are provided herein. The method may include the following steps: receiving, at a computer network, an access request from a client device; retrieving a user identification data associated with said client device; presenting a message over said client device, wherein the message contains details associated with said access request; responsive to the user confirmation of said details, initiating an MFA process, wherein the MFA process comprises presenting an authentication message over the client device; and only in a case that the user has been authenticated by the MFA process, establishing the requested connection access.