Network Access Device Scanning for Remote Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing trend of telework has heightened the risk of secure networks being compromised through unsecure devices on remote networks, particularly Internet of Things (IoT) devices, which can pose threats to corporate networks when accessed remotely.

Innovation Solution

Implementing systems and methods that involve scanning remote networks for unsecure elements before allowing access to a known secure network, and if unsecure elements are detected, denying access or mitigating the security issues by disconnecting from the current remote network, using a virtual private network, or isolating the device from the unsecure element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a corporate device is used to access the corporate network from a remote location, then the device can be used remotely to access corporate resources, but the possibility of nefarious access to the corporate network via unsecure devices on the remote access network increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs a security scan of the remote network environment before allowing access to the corporate network. This preliminary action identifies potential security threats such as unsecure devices, open ports, or vulnerable services on the remote network, and prevents access until the environment is deemed secure or mitigation measures are implemented.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary security scanning mechanism between the corporate device and the corporate network. This intermediary layer assesses the remote network environment and acts as a gatekeeper, allowing access only after verifying security conditions or implementing protective measures such as isolation or encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the system scans the remote network for unsecure elements before allowing access, then the security risk is reduced, but the time required to establish network access increases

Engineering Contradiction:
Improvenetwork security riskVSAvoidaccess establishment time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs a focused security scan targeting specific high-risk elements on the remote network rather than conducting a comprehensive scan of all devices and services. This partial action approach scans only critical areas such as unauthorized devices, open ports, and known vulnerable services, reducing scan time while maintaining effective security assessment.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The security scanning process applies different levels of inspection to different parts of the remote network based on risk assessment. High-priority areas such as devices with known vulnerabilities or unusual network behavior receive more thorough scanning, while low-risk areas receive minimal or no scanning, optimizing the balance between security and access time.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If access is denied when unsecure elements are detected on the remote network, then the corporate network is protected, but the ability to access corporate resources remotely is reduced

Engineering Contradiction:
Improvenetwork security riskVSAvoidremote access flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system converts the presence of unsecure elements on the remote network from a blocking condition into an opportunity for implementing protective measures. Instead of simply denying access, the system applies mitigation strategies such as network isolation, enhanced encryption, or restricted access permissions, thereby maintaining remote access capability while protecting the corporate network from potential threats.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system dynamically adjusts access permissions and security measures based on the security assessment of the remote network environment. When unsecure elements are detected, the system modifies access parameters such as restricting traffic types, implementing additional authentication, or isolating the corporate device from sensitive resources, rather than applying a static deny-all policy.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12225007B2Systems and methods for using a network access device to secure a network prior to requesting access to the network by the network access device
Publication Date: 2025.02.11 FORTINET INC
  • US12225007B2 patent drawing
  • US12225007B2 patent drawing
  • US12225007B2 patent drawing

AI summary

Various approaches for securing networks against access from off network devices. In some cases, embodiments discussed relate to systems and methods for identifying potential threats included in a remote network by a network access device prior to requesting access to a known secure network via the remote network.