Network Access Control Update Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control methods deny access to devices even if only non-critical updates are not current, leading to unnecessary delays due to the requirement of updating both critical and non-critical updates simultaneously.

Innovation Solution

A method that grants network access if all critical updates are current, allowing non-critical updates to be addressed separately and potentially deferred, using an application server, policy manager, and database to manage update timestamps and policy tags.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network requires all updates (critical and non-critical) to be current before granting access, then the network security and compliance are improved, but the user access time and network productivity deteriorate due to lengthy update wait times

Engineering Contradiction:
Improvenetwork securityVSAvoiduser access time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments updates into two distinct categories: critical updates and non-critical updates. This segmentation allows the network access control system to apply different requirements to each type, granting access when critical updates are current while allowing non-critical updates to be deferred, thereby reducing user wait time without compromising security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality standards to different types of updates. Critical updates require current status for access approval, while non-critical updates allow for deferred installation. This local quality approach optimizes the balance between security requirements and user convenience

Inventive Principle:
Principle #3Local quality

2Reliability

If the network requires both critical and non-critical updates to be current before granting access, then the update compliance is improved, but the network productivity and user satisfaction deteriorate due to simultaneous update requirements

Engineering Contradiction:
Improveupdate complianceVSAvoidnetwork productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting update requirements into critical and non-critical categories, the system maintains compliance tracking for both types while allowing selective enforcement. Users can access the network when critical updates are compliant, and non-critical updates can be installed during off-peak times or automatically in the background

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary assessment of update status and grants access based on critical updates being current. Non-critical updates can be scheduled and installed in advance during periods of low network usage, minimizing impact on productivity

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If the network denies access when non-critical updates are not current, then the update policy enforcement is improved, but the user convenience and system usability deteriorate

Engineering Contradiction:
Improvepolicy enforcementVSAvoiduser convenience
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The policy enforcement mechanism is segmented to distinguish between critical and non-critical updates. Automated enforcement ensures critical updates are current for access, while non-critical updates are tracked but do not block access, improving user convenience without completely removing automated policy enforcement

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the enforcement parameter for different update types: strict enforcement for critical updates (access denied if not current) and flexible enforcement for non-critical updates (access granted even if not current). This parameter differentiation maintains policy enforcement integrity while improving user experience

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9560049B2Method and system for optimizing network access control
Publication Date: 2017.01.31 ARRIS ENTERPRISES INC
  • US9560049B2 patent drawing
  • US9560049B2 patent drawing
  • US9560049B2 patent drawing

AI summary

A method and system for optimizing network access control are disclosed. For example, the method includes receiving an access request to a network from a device. Then, the method determines if each one of one or more critical updates of said device is current and if each one of one or more non-critical updates of the device is current. The method concludes by granting the access request to the network if each one of the one or more critical updates of the device is current, even if at least one non-critical update of the one or more non-critical updates of the device is not current.