Dynamic Network Access Control via Presence Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile devices poses a security risk as users can access data from unattended devices, leading to unauthorized access, and existing solutions fail to effectively restrict network access in response to user presence or absence.

Innovation Solution

Implementing a network policy that responds to predefined triggers, such as proximity sensors (RFID, NFC, Bluetooth), device motion, or inactivity, to restrict or restore network access, using combinations of sensors and authentication methods like user credentials or secondary challenges to ensure secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network access is allowed freely for mobile devices, then ease of operation is improved, but security is worsened due to unauthorized access from unattended devices

Engineering Contradiction:
Improvenetwork access availabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network access policy is made dynamic by continuously monitoring sensor data (proximity sensors, motion sensors, inactivity detectors) and automatically adjusting access permissions based on real-time user presence detection. When a user is detected as absent through sensor triggers, network access is automatically restricted; when present, access is restored without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where sensor data about user presence is continuously fed back to the network access control mechanism. The proximity sensors, motion sensors, and inactivity detectors provide ongoing feedback that triggers automatic policy adjustments, creating a closed-loop control system that adapts network access based on actual usage conditions.

Inventive Principle:
Principle #23Feedback

2Reliability

If presence detection sensors are implemented to restrict network access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses multi-functional sensor components that serve both user experience functions (screen dimming, sleep mode triggers) and security functions (presence detection for network access control). By leveraging existing sensors already present in mobile devices for multiple purposes, the solution avoids adding dedicated security hardware, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network access control system is self-regulating through automatic sensor-based detection and policy enforcement. The device monitors its own usage patterns and presence conditions, automatically applying security policies without requiring external security infrastructure or complex manual configuration, thereby reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If network access is restricted based on inactivity, then security is improved, but productivity decreases due to access interruptions

Engineering Contradiction:
ImprovesecurityVSAvoidwork continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial restriction by allowing network access to continue during brief periods of inactivity while only restricting access after a threshold of prolonged inactivity is exceeded. This graduated approach maintains productivity during normal workflow interruptions while still providing security protection for truly abandoned devices, balancing security needs with work continuity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9336356B2Restricting network and device access based on presence detection
Publication Date: 2016.05.10 CISCO TECHNOLOGY INC
  • US9336356B2 patent drawing
  • US9336356B2 patent drawing
  • US9336356B2 patent drawing

AI summary

In an example embodiment, a technique that applies a network policy responsive to specified events, or triggers, to a networked device. If a specified event occurs, the network policy may restrict the device's access to the network. For example, if a user walks away from their networked device, such as a laptop, the device's network access changes. For example, depending upon the policy, network traffic may be blocked or otherwise restricted.