Network Access Control via Compliance Notification Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control systems lack an efficient mechanism to constrain access to network resources based on compliance criteria, such as software updates, which can lead to security vulnerabilities and non-compliant devices accessing sensitive network resources.

Innovation Solution

A computer-implemented method and system that utilizes notification messaging to enforce compliance by transmitting notification messages to client devices, specifying required actions for compliance, and restricting access until the compliance criteria are met, thereby ensuring that only compliant devices gain full access to network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network access control systems allow devices to access network resources without strict compliance verification, then network accessibility and ease of operation are improved, but network security and compliance reliability deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary compliance verification by sending notification messages to client devices before granting network access. The NAC server checks whether devices have received and acknowledged compliance notifications (such as software update requirements) before allowing them to connect to network resources. This preliminary action ensures that only compliant devices gain access, thereby maintaining network security without compromising accessibility for compliant devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network access control systems implement strict compliance verification before granting access, then network security and compliance reliability are improved, but network accessibility and ease of operation worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts network access permissions based on the compliance status of each device. Compliant devices that have acknowledged notification messages are granted full network access, while non-compliant devices receive restricted access or are denied connectivity. This dynamic approach ensures that network security is maintained through selective enforcement, while compliant devices experience no operational barriers, thus preserving ease of operation for the majority of users.

Inventive Principle:
Principle #15Dynamics

3Reliability

If notification messages are sent to all client devices regardless of compliance status, then compliance monitoring coverage is improved, but network resource consumption and system complexity worsen

Engineering Contradiction:
Improvecompliance monitoring coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The notification message system serves multiple functions simultaneously: it acts as a compliance requirement communicator, an access control decision trigger, and a device identification mechanism. The same notification infrastructure used to inform devices of compliance requirements also serves as the basis for determining whether to grant or restrict network access. This multi-functionality eliminates the need for separate complex monitoring systems, thereby maintaining comprehensive compliance coverage while minimizing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10432634B2Gating of full network access pending delivery of notification information
Publication Date: 2019.10.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10432634B2 patent drawing
  • US10432634B2 patent drawing
  • US10432634B2 patent drawing

AI summary

Methods and systems for use in constraining access to network resources based on notification and compliance requirements. In various examples, an access point or similar device receives and stores notification information (e.g., from a network administrator device) for provision to targeted client devices in a notification message. The access point also receives target criteria for use in identifying target client devices that are accessing or attempting to access network resources via the access point. In some embodiments, access to network resources by a targeted client device is constrained pending completion of a compliance condition requirement associated with a notification message. Various levels of access to network resources may be applied to non-compliant target client devices. Following completion of compliance condition, a target client device is exempted from further receipt of the notification message. Select client devices otherwise meeting the target criteria may also be excluded from receiving a notification message.