Network Access Control Update Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control methods deny access to devices even if only non-critical updates are not current, leading to unnecessary delays due to the requirement of updating both critical and non-critical updates simultaneously.
Innovation Solution
A method that grants network access if all critical updates are current, allowing non-critical updates to be addressed separately and potentially deferred, using an application server, policy manager, and database to manage update timestamps and policy tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network requires all updates (critical and non-critical) to be current before granting access, then the network security and compliance are improved, but the user access time and network productivity deteriorate due to lengthy update wait times
Solution Approach 1:
The patent segments updates into two distinct categories: critical updates and non-critical updates. This segmentation allows the network access control system to apply different requirements to each type, granting access when critical updates are current while allowing non-critical updates to be deferred, thereby reducing user wait time without compromising security
Solution Approach 2:
The patent applies different quality standards to different types of updates. Critical updates require current status for access approval, while non-critical updates allow for deferred installation. This local quality approach optimizes the balance between security requirements and user convenience
2Reliability
If the network requires both critical and non-critical updates to be current before granting access, then the update compliance is improved, but the network productivity and user satisfaction deteriorate due to simultaneous update requirements
Solution Approach 1:
By segmenting update requirements into critical and non-critical categories, the system maintains compliance tracking for both types while allowing selective enforcement. Users can access the network when critical updates are compliant, and non-critical updates can be installed during off-peak times or automatically in the background
Solution Approach 2:
The system performs preliminary assessment of update status and grants access based on critical updates being current. Non-critical updates can be scheduled and installed in advance during periods of low network usage, minimizing impact on productivity
3Extent of automation
If the network denies access when non-critical updates are not current, then the update policy enforcement is improved, but the user convenience and system usability deteriorate
Solution Approach 1:
The policy enforcement mechanism is segmented to distinguish between critical and non-critical updates. Automated enforcement ensures critical updates are current for access, while non-critical updates are tracked but do not block access, improving user convenience without completely removing automated policy enforcement
Solution Approach 2:
The system changes the enforcement parameter for different update types: strict enforcement for critical updates (access denied if not current) and flexible enforcement for non-critical updates (access granted even if not current). This parameter differentiation maintains policy enforcement integrity while improving user experience
Data Source
AI summary
A method and system for optimizing network access control are disclosed. For example, the method includes receiving an access request to a network from a device. Then, the method determines if each one of one or more critical updates of said device is current and if each one of one or more non-critical updates of the device is current. The method concludes by granting the access request to the network if each one of the one or more critical updates of the device is current, even if at least one non-critical update of the one or more non-critical updates of the device is not current.


