Network Access Control via Trusted Point Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The security of user data is compromised when an electronic device switches to a free WI-FI network set up by a hacker, as existing technologies fail to adequately control network access and prevent unauthorized access.
Innovation Solution
A network access control method and apparatus that configures network access permissions to allow access only through trusted network access points, prohibiting access through untrusted points, ensuring secure network resource access by identifying and managing network access points based on trust levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the electronic device allows free network switching to maintain connectivity, then network adaptability is improved, but security of user data deteriorates due to unauthorized access through hacker-established APs
Solution Approach 1:
The patent segments network access points into trusted and untrusted categories based on pre-configured network identifiers (SSID, BSSID, MAC address). The system divides network access control into application-level permissions and network-level trust verification, creating multiple layers of security segmentation that allow adaptive network switching while maintaining data security through selective access control.
2Reliability
If the system implements strict network access control to prevent unauthorized access, then security of user data is improved, but network adaptability deteriorates as the device cannot switch to available networks
Solution Approach 1:
The patent implements dynamic network access control where the system adapts its behavior based on the current network context. When a trusted network is detected, applications can access network resources freely. When an untrusted network is detected, the system dynamically restricts access based on application permissions. This dynamic adjustment resolves the contradiction by making security control flexible rather than rigid.
Solution Approach 2:
The system changes network access parameters (permission levels, access restrictions) based on network trust status. Pre-configured network identifiers serve as parameters that determine whether a network is trusted. When network parameters match pre-configured values, full access is granted; otherwise, restricted access is applied. This parameter-based approach enables both security and adaptability.
3Ease of operation
If the device connects to any available network to maintain application functionality, then ease of operation is improved, but harmful factors increase due to data theft by hackers
Solution Approach 1:
The patent applies preliminary anti-action by pre-configuring trusted network identifiers (SSID, BSSID, MAC address) before the device encounters potential security threats. This advance preparation creates a security framework that automatically prevents connection to untrusted networks or restricts application access on untrusted networks, countering potential data theft before it can occur while maintaining seamless application operation on trusted networks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides a network access control method and apparatus. The network access control method includes: configuring network access permission of a first application, where the network access permission includes allowing the first application to access a network resource by using a first type of network access point, and the first type of network access point includes at least one first network access point; accessing a second network access point, where the second network access point belongs to the first type of network access point; when the first application is running, allowing the first application to access the network resource by using the second network access point; and when a third network access point is accessed, if the third network access point does not belong to the first type of network access point, prohibiting the first application from accessing the network resource by using the third network access point, thereby improving network security; further, when an electronic device accesses a network resource with relatively high security, security of a user resource that uses the electronic device can be improved.