Network Access Control Segmentation for Multilevel Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-attached multilevel security systems face increased server load and reduced communication speed when dealing with numerous client terminals, and user convenience is compromised due to authentication failures and insufficient access control.

Innovation Solution

A system where clients and servers communicate through network access control means, with clients controlling access requests based on security levels and servers determining the authenticity of these requests, authorizing or controlling access accordingly, and employing provisional security levels to manage access when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a gateway or server collectively performs access control in a network-attached multilevel security system, then security control is centralized and consistent, but the load of the gateway or server increases and communication speed is reduced when there are a number of client terminals

Engineering Contradiction:
Improvesecurity control consistencyVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access control function is segmented between the server (second network access control means) and client terminals (first network access control means). The server determines whether the client has the first network access control means and delegates authorization to clients that do, distributing the control load while maintaining security consistency through the server's oversight role.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a gateway or server collectively performs access control in a network-attached multilevel security system, then security control is centralized and consistent, but the load of the gateway or server increases when there are a number of client terminals

Engineering Contradiction:
Improvesecurity control consistencyVSAvoidserver load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Client terminals with the first network access control means perform self-service by autonomously controlling their own network access requests based on security levels. The server only performs determination and authorization, significantly reducing its processing load compared to collectively handling all access control decisions.

Inventive Principle:
Principle #25Self-service

3Reliability

If the host device executes user authentication by referencing an authentication history in the host device when the host device cannot access a security management server, then authentication can proceed without server access, but when the authentication history is not stored in the host device, a user successfully authenticated when authenticated in a security management server fails in the authentication, thus lacking convenience of a user task

Engineering Contradiction:
Improveauthentication availabilityVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The first network access control means acts as an intermediary that stores and manages authentication history locally in the client terminal. This intermediary role ensures authentication continuity and convenience by maintaining authentication state without requiring direct server access for each authentication operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the blocking device recognizes failed authentication when the IP address of the client terminal is not contained in access management information and blocks the access request, then security is maintained, but when the client terminal has failed in authentication due to being brought from the outside of a company, the client terminal does not access a server of a company and convenience of a user task is insufficient

Engineering Contradiction:
Improvesecurity enforcementVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The server's access control behavior is made dynamic based on the determination result. When the client has the first network access control means, the server authorizes access requests dynamically without blocking. When the client lacks this means, the server controls access based on security levels. This dynamic adaptation maintains security while improving convenience for legitimate users.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9076011B2Secret information leakage prevention system, secret information leakage prevention method and secret information leakage prevention program
Publication Date: 2015.07.07 NEC CORP
  • US9076011B2 patent drawing
  • US9076011B2 patent drawing
  • US9076011B2 patent drawing

AI summary

Provided is a system in which two or more clients, each including an application program that transmits a network access request, and a server are able to communicate, wherein at least one client includes first control means for controlling the access request transmitted to the server, based on a security level assigned to the application program, and the server includes second control means for determining whether the first control means has been introduced to the client that has transmitted the access request, authorizing the access request when the determination result is positive, and controlling the access request based on a security level assigned to an access target when the determination result is negative.