Network Access Control via Trusted Point Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of user data is compromised when an electronic device switches to a free WI-FI network set up by a hacker, as existing technologies fail to adequately control network access and prevent unauthorized access.

Innovation Solution

A network access control method and apparatus that configures network access permissions to allow access only through trusted network access points, prohibiting access through untrusted points, ensuring secure network resource access by identifying and managing network access points based on trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the electronic device allows free network switching to maintain connectivity, then network adaptability is improved, but security of user data deteriorates due to unauthorized access through hacker-established APs

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidsecurity of user data
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network access points into trusted and untrusted categories based on pre-configured network identifiers (SSID, BSSID, MAC address). The system divides network access control into application-level permissions and network-level trust verification, creating multiple layers of security segmentation that allow adaptive network switching while maintaining data security through selective access control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system implements strict network access control to prevent unauthorized access, then security of user data is improved, but network adaptability deteriorates as the device cannot switch to available networks

Engineering Contradiction:
Improvesecurity of user dataVSAvoidnetwork adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network access control where the system adapts its behavior based on the current network context. When a trusted network is detected, applications can access network resources freely. When an untrusted network is detected, the system dynamically restricts access based on application permissions. This dynamic adjustment resolves the contradiction by making security control flexible rather than rigid.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes network access parameters (permission levels, access restrictions) based on network trust status. Pre-configured network identifiers serve as parameters that determine whether a network is trusted. When network parameters match pre-configured values, full access is granted; otherwise, restricted access is applied. This parameter-based approach enables both security and adaptability.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the device connects to any available network to maintain application functionality, then ease of operation is improved, but harmful factors increase due to data theft by hackers

Engineering Contradiction:
Improveapplication continuityVSAvoiddata theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-configuring trusted network identifiers (SSID, BSSID, MAC address) before the device encounters potential security threats. This advance preparation creates a security framework that automatically prevents connection to untrusted networks or restricts application access on untrusted networks, countering potential data theft before it can occur while maintaining seamless application operation on trusted networks.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP4037359B1Network access control method and apparatus
Publication Date: 2024.02.21 HUAWEI DEVICE CO LTD
  • EP4037359B1 patent drawingFigure 1
  • EP4037359B1 patent drawingFigure 2
  • EP4037359B1 patent drawingFigure 3

AI summary

The present invention provides a network access control method and apparatus. The network access control method includes: configuring network access permission of a first application, where the network access permission includes allowing the first application to access a network resource by using a first type of network access point, and the first type of network access point includes at least one first network access point; accessing a second network access point, where the second network access point belongs to the first type of network access point; when the first application is running, allowing the first application to access the network resource by using the second network access point; and when a third network access point is accessed, if the third network access point does not belong to the first type of network access point, prohibiting the first application from accessing the network resource by using the third network access point, thereby improving network security; further, when an electronic device accesses a network resource with relatively high security, security of a user resource that uses the electronic device can be improved.