Network Access Control Server for Dynamic Asset Quarantine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are insufficient in controlling access and managing vulnerabilities, as they often focus on single discrete vulnerabilities, are costly, and may have known or unknown holes, leading to exposure to various threats from both authorized and unauthorized clients.

Innovation Solution

A system and method that dynamically obtain information about network assets, compare device identifiers to policy constraints, and quarantine devices from the network if they do not comply, using a combination of self-discovery methods, assets database, and policy database to enforce uniform security policies and segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple discrete security solutions (firewalls, authentication servers, patch management) are implemented to control network access, then specific security vulnerabilities are addressed, but the overall system complexity increases and coverage gaps remain

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple discrete security functions (authentication, authorization, asset management, policy enforcement) into a single integrated NAC server that maintains databases of network assets and policies, and coordinates all access control decisions in one centralized location, thereby reducing system complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The NAC server performs multiple security functions simultaneously: it authenticates devices, authorizes access levels, monitors network assets, enforces policies, and dynamically quarantines threats. This multi-functional approach replaces the need for separate specialized security systems, reducing overall complexity while improving reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If continuous network auditing and monitoring are performed to identify security threats, then network vulnerability detection improves, but network performance and available bandwidth are degraded

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs partial monitoring by selectively auditing only authentication traffic and policy-relevant communications rather than all network traffic. The NAC server focuses monitoring efforts on critical security functions while allowing normal network traffic to flow uninterrupted, thus maintaining threat detection capability without significantly degrading network throughput

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The NAC server acts as an intermediary that handles all authentication and authorization traffic, performing security checks at this intermediate layer. This allows the system to monitor and control security-critical communications without needing to inspect or process every data packet flowing through the network, preserving network performance while maintaining detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If unauthorized devices are immediately denied network access, then network security is improved, but legitimate devices with temporary issues (unpatched software, missing certificates) are incorrectly blocked

Engineering Contradiction:
Improveaccess control securityVSAvoidlegitimate access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication and policy verification before granting full network access. Devices undergo initial checks against the asset database and policy rules, and those that fail temporarily can be placed in a restricted quarantine VLAN where they can receive patches or certificates before being fully authorized, preventing incorrect blocking of legitimate devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network is segmented into different access levels using VLANs: fully authorized devices access the main network, while devices with temporary issues are segregated into quarantine zones with limited access. This segmentation allows the system to maintain strict security controls while providing appropriate access to legitimate devices based on their current compliance status

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8407240B2Autonomic self-healing network
Publication Date: 2013.03.26 KYNDRYL INC
  • US8407240B2 patent drawing
  • US8407240B2 patent drawing
  • US8407240B2 patent drawing

AI summary

A system and method capable of obtaining information dynamically of assets residing on a network. The system and method further capable of comparing a device identifier to the dynamically obtained information of assets and policies at a time of a request to access the network and determining whether the device identifier matches at least one of the dynamically obtained information of assets and policies. The system and method further capable of quarantining the device from the network or a portion thereof based upon the determining.