Network Access Control via Combined Client and Trusted Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures are inadequate in preventing malware infections and unauthorized access to malicious websites, as they can become outdated quickly and are often disabled by malware, allowing infections to occur before updates can be applied, and they lack effective control over client options.

Innovation Solution

A system and method for controlling network content access by combining client and trusted site profiles, using a network access server with a combining engine and filtering engine to ensure access rules are enforced, allowing only compliant requests to proceed, and enabling automatic updates to ensure the latest security measures are applied.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional antivirus and firewall applications are installed on client processors, then malware protection is provided, but the protection becomes outdated quickly and can be disabled by malware

Engineering Contradiction:
Improvemalware protection effectivenessVSAvoidtime lag in updating security measures
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A network access server acts as an intermediary between clients and the network, centralizing security control. The server hosts updated security profiles and filters network traffic, preventing malware from reaching clients before they can disable local protections. This mediator approach ensures clients receive current security measures without relying on timely local updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security profiles and filtering rules are prepared and updated in advance on the network access server before malware can infect clients. The server pre-configures protection mechanisms that are applied to network traffic before it reaches client processors, preventing the time-lag problem where local antivirus software becomes outdated after infection occurs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If client processors run local antivirus and security software, then protection is provided, but client options and control are excessive and difficult to manage

Engineering Contradiction:
Improvesecurity protectionVSAvoidcontrol and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security control functions are extracted from individual client processors and centralized on the network access server. The server handles profile management, update distribution, and filtering decisions, removing the complexity of managing multiple client-based security systems. Clients simply receive and apply centrally-managed security profiles.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network access server provides universal security control for all clients through a single platform. It performs multiple functions including hosting security profiles, filtering network traffic, updating protections, and managing access rules, replacing the need for each client to independently manage its own security software.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If content assessment is performed to control network access, then access security is improved, but access speed is reduced

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security profiles and filtering rules are pre-configured and stored on the network access server before access requests occur. When clients request network access, the server applies pre-established rules rather than performing real-time content assessment, maintaining both security and speed by avoiding on-the-fly analysis of each access request.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2710780B1Network access control system and method
Publication Date: 2019.04.17 WHATEVER SOFTWARE CONTRACTS
  • EP2710780B1 patent drawingFigure 1~2
  • EP2710780B1 patent drawingFigure 3~4
  • EP2710780B1 patent drawingFigure 5

AI summary

A system comprises a client (10) that can place a network site (18) access request to a network access server (14). Sometime prior to placing the request, the client has already accessed the network access server (14) to set up a network access profile relating to personal choices and has accessed a trusted site (16) to select one or more options to provide a trusted site profile. When the client (10) places a request, client data is provided along with the request whereby the client is automatically recognized by the network access server (14). The network access server, upon recognition of the client, passes the client data to the trusted site (16), the trusted site (16) uses the client data to retrieve the client's (10) trusted site profile, and the trusted site (16) transfers the trusted site profile to the network access server (14). A combining engine in the network access server (14) then combines the trusted site profile with the network access profile and a filtering engine applies the combined profiles to permit or forbid the network site (18) request to be fulfilled.