Network Access Control via Building Location Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in ensuring secure access to protected network resources, particularly when users move in and out of restricted areas, as they do not effectively account for users' physical location and may allow unauthorized access if they bypass exit barriers or are disconnected from the network.
Innovation Solution
A method and system that integrates building access control with network access control, where user credentials are verified against predetermined information, and the user's location is checked through an access control system, requiring additional authentication if they are not recorded as being within the restricted area, and updating records upon disconnection from the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If building access control is integrated with network access control to verify user location, then network security is improved, but system complexity increases
Solution Approach 1:
The patent combines building access control system and network access control system into a unified authentication mechanism. The network access controller integrates with the building access controller to share user location data, eliminating the need for separate authentication systems and reducing overall system complexity while improving security.
Solution Approach 2:
The patent introduces an intermediary mechanism where the building access controller acts as a mediator that provides user location information to the network access controller. This intermediary approach allows the two systems to work together without direct complex integration, simplifying the overall architecture while maintaining security.
2Reliability
If additional authentication checks are performed to verify user presence in restricted area, then unauthorized access is reduced, but user authentication time increases
Solution Approach 1:
The patent performs preliminary authentication by checking user location information from the building access control system before initiating network authentication. This preliminary check verifies whether the user is physically present in the restricted area, preventing unnecessary authentication delays for users who are not authorized to be in the location.
Solution Approach 2:
The system implements feedback mechanisms where the network access controller continuously monitors user location status and network connection state. Based on this feedback, the system dynamically adjusts authentication requirements, reducing delays for legitimate users while maintaining security for unauthorized access attempts.
3Ease of operation
If network access is granted based on building access records, then convenience for authorized users is improved, but vulnerability to bypassed exit barriers increases
Solution Approach 1:
The patent implements dynamic authentication that adapts to real-time conditions. The system continuously monitors both building access records and current network connection status, adjusting access decisions based on dynamic information rather than relying solely on static building access records. This dynamic approach maintains convenience for authorized users while detecting potential security breaches.
Solution Approach 2:
The system applies preliminary anti-action by implementing additional verification steps when anomalies are detected in building access records. If a user's network activity doesn't match their building access status or if exit barrier bypasses are suspected, the system preemptively blocks access or requests additional authentication, preventing potential security issues before they can be exploited.
Data Source
Figure 1
Figure 2
AI summary
A system and method for controlling access to a protected network resource is provided. Access is controlled as follows. User credentials received with a request from a user for access to the protected network resource are checked against predetermined user information so as to authenticate the user; The request is made via a network access point located within a restricted area. The recorded location of the user is checked to determine whether the user is recorded as being within the restricted area. Access to the protected network resource is allowed if the user credentials are authenticated and the user is recorded as being within the restricted area. The user's network connection is monitored and, on detection that the user is disconnected from the network, the user is recorded as not located within the restricted area. Additional credentials are required from the user to support the user's request when the user is not recorded as being within the restricted area.