Network Access Control Segmentation for Multilevel Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network-attached multilevel security systems face increased server load and reduced communication speed when dealing with numerous client terminals, and user convenience is compromised due to authentication failures and insufficient access control.
Innovation Solution
A system where clients and servers communicate through network access control means, with clients controlling access requests based on security levels and servers determining the authenticity of these requests, authorizing or controlling access accordingly, and employing provisional security levels to manage access when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a gateway or server collectively performs access control in a network-attached multilevel security system, then security control is centralized and consistent, but the load of the gateway or server increases and communication speed is reduced when there are a number of client terminals
Solution Approach 1:
The access control function is segmented between the server (second network access control means) and client terminals (first network access control means). The server determines whether the client has the first network access control means and delegates authorization to clients that do, distributing the control load while maintaining security consistency through the server's oversight role.
2Reliability
If a gateway or server collectively performs access control in a network-attached multilevel security system, then security control is centralized and consistent, but the load of the gateway or server increases when there are a number of client terminals
Solution Approach 1:
Client terminals with the first network access control means perform self-service by autonomously controlling their own network access requests based on security levels. The server only performs determination and authorization, significantly reducing its processing load compared to collectively handling all access control decisions.
3Reliability
If the host device executes user authentication by referencing an authentication history in the host device when the host device cannot access a security management server, then authentication can proceed without server access, but when the authentication history is not stored in the host device, a user successfully authenticated when authenticated in a security management server fails in the authentication, thus lacking convenience of a user task
Solution Approach 1:
The first network access control means acts as an intermediary that stores and manages authentication history locally in the client terminal. This intermediary role ensures authentication continuity and convenience by maintaining authentication state without requiring direct server access for each authentication operation.
4Reliability
If the blocking device recognizes failed authentication when the IP address of the client terminal is not contained in access management information and blocks the access request, then security is maintained, but when the client terminal has failed in authentication due to being brought from the outside of a company, the client terminal does not access a server of a company and convenience of a user task is insufficient
Solution Approach 1:
The server's access control behavior is made dynamic based on the determination result. When the client has the first network access control means, the server authorizes access requests dynamically without blocking. When the client lacks this means, the server controls access based on security levels. This dynamic adaptation maintains security while improving convenience for legitimate users.
Data Source
AI summary
Provided is a system in which two or more clients, each including an application program that transmits a network access request, and a server are able to communicate, wherein at least one client includes first control means for controlling the access request transmitted to the server, based on a security level assigned to the application program, and the server includes second control means for determining whether the first control means has been introduced to the client that has transmitted the access request, authorizing the access request when the determination result is positive, and controlling the access request based on a security level assigned to an access target when the determination result is negative.


