Network Access Authentication via Content Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in authenticating devices that have connected to untrusted networks, which can compromise enterprise security, especially with the increasing mobility of devices and the risk of man-in-the-middle attacks in wireless networks.

Innovation Solution

A content authentication method that evaluates the device's content before granting access to a network, using techniques such as virus scans, program reinstalls, and configuration setting resets, based on predefined criteria and network properties, to ensure integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong security techniques are implemented to prevent unauthorized access, then network security is improved, but it becomes difficult to monitor the content of communication

Engineering Contradiction:
Improvenetwork securityVSAvoidcontent monitoring capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary content evaluation and authentication before granting network access. Device content is scanned and verified against security policies in advance, allowing security checks to be completed before the device connects to the enterprise network, thus enabling both strong security and content monitoring

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If devices are allowed to connect to untrusted networks for mobility, then ease of use is improved, but device integrity and network security are compromised

Engineering Contradiction:
Improvedevice mobilityVSAvoiddevice integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary content evaluation and authentication before granting network access. Device content is scanned and verified against security policies in advance, allowing security checks to be completed before the device connects to the enterprise network, thus enabling both strong security and content monitoring

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors device content and network connections, providing feedback to the authentication server. When a device connects to an untrusted network, the system detects this through token alteration or logging mechanisms and triggers re-authentication or content re-evaluation, creating a closed-loop security system that adapts to changing conditions

Inventive Principle:
Principle #23Feedback

3Reliability

If content evaluation is performed on all devices before access, then network security is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different levels of content evaluation based on local conditions. Devices connecting from untrusted networks undergo full content scanning, while devices from trusted networks receive streamlined authentication. The authentication server adjusts the depth and scope of content evaluation based on the device's connection history and current risk level

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication server performs multiple functions including content evaluation, device authentication, access control policy enforcement, and security monitoring. By consolidating these functions into a single universal system, the patent reduces overall system complexity while maintaining comprehensive security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7752320B2Method and apparatus for content based authentication for network access
Publication Date: 2010.07.06 AVAYA INC
  • US7752320B2 patent drawing
  • US7752320B2 patent drawing
  • US7752320B2 patent drawing

AI summary

A method and apparatus are provided for authenticating the contents of a device requesting access to a first network, such as an enterprise network. If a device has connected to at least one other network then the content of the device is evaluated prior to obtaining access. The scope of the content evaluation may be based, for example, on properties of the other network or on one or more defined content authentication rules. If a device attempts to access a network, the content of the device is evaluated and the device may be restricted to accessing only one or more restoration services if the content fails to satisfy one or more predefined criteria, such as a content item that is out of date or a determination that the device connected to one or more external networks. The restoration service(s) can update a content item that is out of date, reinstall one or more programs or return configuration settings to default values.