Network Access Controller Using RFID Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In secured sites, managing the security versions and levels of OS and applications across multiple information terminals is challenging, leading to potential vulnerabilities due to individual administrators' limitations in maintaining up-to-date security, especially when multiple users share terminals or when terminals are not started.

Innovation Solution

A controller system that uses an RFID reader to collect and assess security information from information terminals before network access, determining access permission based on stored security data and criteria, and generates control signals to permit or block access, ensuring only secure terminals connect to the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual administrators manage security updates on information terminals, then each terminal can be configured with security software, but the versions and management levels of OS and applications cannot be kept always up-to-date

Engineering Contradiction:
Improvesecurity levelVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The controller receives security information from multiple information terminals, evaluates it against stored criteria, and sends evaluation results back to the terminals. This feedback loop ensures continuous monitoring and automatic updates of security versions across all terminals, resolving the contradiction between maintaining high security levels and managing multiple terminals efficiently.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Each information terminal automatically transmits its security information (OS version, application versions, antivirus status) to the controller without requiring manual intervention. The controller then automatically evaluates and manages updates, enabling the system to self-manage security across multiple terminals without burdening individual administrators.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security information is manually checked on each terminal, then security status can be monitored, but the process is time-consuming and prone to human error

Engineering Contradiction:
Improvesecurity information accuracyVSAvoidmonitoring time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The manual mechanical process of checking security information on each terminal is replaced with an automated electronic system. The controller automatically receives, stores, and evaluates security information from all terminals through electronic communication, eliminating human error and significantly reducing the time required for security monitoring while improving accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If access control is implemented at the network level, then unauthorized access can be prevented, but terminals with outdated security may still connect to the network

Engineering Contradiction:
Improveunauthorized access riskVSAvoidsecurity vulnerability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The controller performs preliminary evaluation of security information from each terminal before permitting network access. Security criteria are established in advance, and the controller automatically compares terminal security status against these criteria. Only terminals meeting the security requirements are granted access, preventing both unauthorized access and connections from vulnerable terminals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The controller acts as an intermediary between information terminals and the network. It receives security information from terminals, evaluates it against stored criteria, and based on this evaluation, either permits or blocks access to the network. This intermediary role ensures that both unauthorized access and security vulnerabilities are filtered before network connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Automatically ensures that only information terminals with up-to-date security configurations can access the network, preventing unauthorized access and reducing the risk of information leakage by managing security versions centrally and proactively.

Implementation Method 1

the controller may receive, through an RFID reader, the security information stored in an RFID tag included in the information terminal

Methodology Applied
Scientific EffectRFID (Radio Frequency Identification): Electromagnetic Induction

Data Source

PatentUS10178099B2System for monitoring access to network within secured site
Publication Date: 2019.01.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10178099B2 patent drawing
  • US10178099B2 patent drawing
  • US10178099B2 patent drawing

AI summary

A controller is provided which monitors/manages information terminals' access to a network within a secured site. A controller of the present invention includes: a storage device for storing security information about at least one or more information terminals received from the information terminals before accessing a network; and a processor for determining whether to permit access of an information terminal to the network based on the security information read from the storage device and access permission criteria on the security information, and generating a control signal for permitting or blocking the access of the information terminal to the network according to the determination result.