Network Access Control via Compliance Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a reliable and efficient network access control system that ensures fast, reliable, and secure communications over computer networks, particularly for stakeholders with facilities in different geographic locations, as existing solutions like leased lines are costly and vulnerable to security threats.

Innovation Solution

An apparatus and method that utilize a criteria engine to generate and monitor security criteria, a checker to assess compliance, and a communicator to enforce access control based on compliance levels, including actions such as disconnecting or quarantining users, to manage network access securely and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If virtual private networks are used to enable cost-efficient communication between computers at different geographic locations, then communication cost is reduced, but network security risk increases

Engineering Contradiction:
Improvecommunication costVSAvoidnetwork security risk
Core Design Contradiction:
Loss of energyVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments by evaluating compliance criteria before granting network access. The apparatus checks security policies, antivirus status, firewall configurations, and other security parameters in advance, and only allows devices that meet the predetermined compliance thresholds to connect to the network, thereby preventing security risks before they can affect the network

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary access control apparatus that mediates between the VPN connection and the network. This intermediary evaluates compliance criteria, assesses security policies, and controls access based on the evaluation results, acting as a security buffer between potentially risky external connections and the internal network

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security criteria are monitored for all users, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security assessment system is segmented into multiple independent components: a criteria engine that generates compliance criteria, a checker that evaluates security parameters, a profile engine that manages user profiles and policies, and an access controller that enforces decisions. Each component has a specific function, making the overall complex system manageable through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The apparatus uses universal compliance criteria that can be applied across all users and devices. The same security policies, antivirus requirements, and firewall configurations are uniformly enforced for all network access requests, simplifying management by avoiding the need for completely separate assessment mechanisms for different user types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8438619B2Network access control
Publication Date: 2013.05.07 MOBILE SONIC INC
  • US8438619B2 patent drawing
  • US8438619B2 patent drawing
  • US8438619B2 patent drawing

AI summary

An system for controlling access to a network by a user device. The system includes a criteria engine that generates a plurality of criteria to be monitored on the user device and a checker that generates at least one check for each of the plurality of criteria. The system further includes a profiler that retrieves a profile for the user device, the profile including the plurality of criteria and the at least one check for each of the plurality of criteria, a comparator that compares a summary of the retrieved profile to a summary of a profile received from the user device and a communicator that communicates a message to the user device based on the comparison.