Network Access Control via Compliance Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a reliable and efficient network access control system that ensures fast, reliable, and secure communications over computer networks, particularly for stakeholders with facilities in different geographic locations, as existing solutions like leased lines are costly and vulnerable to security threats.
Innovation Solution
An apparatus and method that utilize a criteria engine to generate and monitor security criteria, a checker to assess compliance, and a communicator to enforce access control based on compliance levels, including actions such as disconnecting or quarantining users, to manage network access securely and efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If virtual private networks are used to enable cost-efficient communication between computers at different geographic locations, then communication cost is reduced, but network security risk increases
Solution Approach 1:
The system performs preliminary security assessments by evaluating compliance criteria before granting network access. The apparatus checks security policies, antivirus status, firewall configurations, and other security parameters in advance, and only allows devices that meet the predetermined compliance thresholds to connect to the network, thereby preventing security risks before they can affect the network
Solution Approach 2:
The patent introduces an intermediary access control apparatus that mediates between the VPN connection and the network. This intermediary evaluates compliance criteria, assesses security policies, and controls access based on the evaluation results, acting as a security buffer between potentially risky external connections and the internal network
2Reliability
If comprehensive security criteria are monitored for all users, then network security is improved, but system complexity increases
Solution Approach 1:
The security assessment system is segmented into multiple independent components: a criteria engine that generates compliance criteria, a checker that evaluates security parameters, a profile engine that manages user profiles and policies, and an access controller that enforces decisions. Each component has a specific function, making the overall complex system manageable through modular design
Solution Approach 2:
The apparatus uses universal compliance criteria that can be applied across all users and devices. The same security policies, antivirus requirements, and firewall configurations are uniformly enforced for all network access requests, simplifying management by avoiding the need for completely separate assessment mechanisms for different user types
Data Source
AI summary
An system for controlling access to a network by a user device. The system includes a criteria engine that generates a plurality of criteria to be monitored on the user device and a checker that generates at least one check for each of the plurality of criteria. The system further includes a profiler that retrieves a profile for the user device, the profile including the plurality of criteria and the at least one check for each of the plurality of criteria, a comparator that compares a summary of the retrieved profile to a summary of a profile received from the user device and a communicator that communicates a message to the user device based on the comparison.


