Network Access Control via Segmented Authentication and Policy Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network access control systems using 802.1x switches cannot precisely control network access rights for terminals, allowing unrestricted access once access is enabled, leading to security vulnerabilities.

Innovation Solution

A method and system involving bi-directional and solo-directional encryption for terminal identity authentication, with a server and security access control gateway to control network access and deliver security policies, ensuring precise control over terminal access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 802.1x switch controls network access right by enabling or disabling access, then network access control is implemented, but terminal can browse all information without limitation leading to imprecise security control

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the access control function into two parts: the 802.1x switch handles basic access authorization (enabling/disabling), while a security gateway handles fine-grained resource-level access control. This segmentation allows each component to specialize, with the gateway providing precise control over specific network resources based on terminal identity and security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security gateway acts as an intermediary between the terminal and the Intranet/Extranet. It receives authenticated terminals from the 802.1x switch and applies additional security policies to control access to specific network resources. This intermediary layer adds precision to access control without compromising the basic access management function of the switch.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security control software is installed in each terminal with security policy from server, then security monitoring is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security control software on terminals operates autonomously by executing security policies delivered from the server. The terminal itself performs the monitoring and control actions based on received policies, reducing the need for continuous centralized management intervention and simplifying the overall system operation despite the presence of distributed software.

Inventive Principle:
Principle #25Self-service

3Reliability

If bi-directional encryption is used for terminal identity information, then authentication security is improved, but processing complexity increases compared to solo-directional encryption

Engineering Contradiction:
Improveauthentication securityVSAvoidencryption processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption process is segmented into two stages: first, bi-directional encryption between terminal and server for secure identity verification; second, solo-directional encryption by the server when forwarding identity information to the security gateway. This segmentation allows each encryption method to be used where most appropriate, balancing security requirements with processing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The terminal performs bi-directional encryption with the server in advance during the authentication phase. Once authenticated, the server caches the verified identity information and uses simpler solo-directional encryption when communicating with the security gateway. This preliminary authentication action reduces subsequent processing complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8407462B2Method, system and server for implementing security access control by enforcing security policies
Publication Date: 2013.03.26 CHENGDU HUAWEI TECH CO LTD
  • US8407462B2 patent drawing
  • US8407462B2 patent drawing
  • US8407462B2 patent drawing

AI summary

A method for implementing network security access control is provided, including: receiving and decrypting terminal identity information that is encrypted in a bi-directional encryption mode and forwarded by a switch, and authenticating the decrypted terminal identity information; returning an authentication result to the switch so that the switch controls access of a terminal to a network according to the authentication result; encrypting the decrypted terminal identity information in a solo-directional encryption mode and authenticating the encrypted terminal identity information; returning an authentication result to a security access control gateway so that the security access control gateway controls access of the terminal to network resources according to the authentication result; delivering a security policy to a security control module on the terminal so that the security control module controls the terminal according to the security policy. A server is provided, including a first authentication module and a second authentication module. A system for implementing network security access control is provided, including a server, a switch, a security access control gateway and a terminal.