Network Access Control via Segmented Authentication and Policy Gateways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network access control systems using 802.1x switches cannot precisely control network access rights for terminals, allowing unrestricted access once access is enabled, leading to security vulnerabilities.
Innovation Solution
A method and system involving bi-directional and solo-directional encryption for terminal identity authentication, with a server and security access control gateway to control network access and deliver security policies, ensuring precise control over terminal access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 802.1x switch controls network access right by enabling or disabling access, then network access control is implemented, but terminal can browse all information without limitation leading to imprecise security control
Solution Approach 1:
The patent segments the access control function into two parts: the 802.1x switch handles basic access authorization (enabling/disabling), while a security gateway handles fine-grained resource-level access control. This segmentation allows each component to specialize, with the gateway providing precise control over specific network resources based on terminal identity and security policies.
Solution Approach 2:
The security gateway acts as an intermediary between the terminal and the Intranet/Extranet. It receives authenticated terminals from the 802.1x switch and applies additional security policies to control access to specific network resources. This intermediary layer adds precision to access control without compromising the basic access management function of the switch.
2Reliability
If security control software is installed in each terminal with security policy from server, then security monitoring is achieved, but system complexity increases
Solution Approach 1:
The security control software on terminals operates autonomously by executing security policies delivered from the server. The terminal itself performs the monitoring and control actions based on received policies, reducing the need for continuous centralized management intervention and simplifying the overall system operation despite the presence of distributed software.
3Reliability
If bi-directional encryption is used for terminal identity information, then authentication security is improved, but processing complexity increases compared to solo-directional encryption
Solution Approach 1:
The encryption process is segmented into two stages: first, bi-directional encryption between terminal and server for secure identity verification; second, solo-directional encryption by the server when forwarding identity information to the security gateway. This segmentation allows each encryption method to be used where most appropriate, balancing security requirements with processing complexity.
Solution Approach 2:
The terminal performs bi-directional encryption with the server in advance during the authentication phase. Once authenticated, the server caches the verified identity information and uses simpler solo-directional encryption when communicating with the security gateway. This preliminary authentication action reduces subsequent processing complexity while maintaining security.
Data Source
AI summary
A method for implementing network security access control is provided, including: receiving and decrypting terminal identity information that is encrypted in a bi-directional encryption mode and forwarded by a switch, and authenticating the decrypted terminal identity information; returning an authentication result to the switch so that the switch controls access of a terminal to a network according to the authentication result; encrypting the decrypted terminal identity information in a solo-directional encryption mode and authenticating the encrypted terminal identity information; returning an authentication result to a security access control gateway so that the security access control gateway controls access of the terminal to network resources according to the authentication result; delivering a security policy to a security control module on the terminal so that the security control module controls the terminal according to the security policy. A server is provided, including a first authentication module and a second authentication module. A system for implementing network security access control is provided, including a server, a switch, a security access control gateway and a terminal.


