Network Access Control via Authorized Tunnel for Packet Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control technologies, such as ARP spoofing and VPNs, are vulnerable to security breaches, particularly at the application and transport layers, and face challenges in managing data packet flow effectively, with ARP spoofing putting a load on the network and VPNs being susceptible to post-tunnel data packet management issues.
Innovation Solution
A system and method that utilize a node with a communication circuit, processor, and memory to detect network access events, identify authorized tunnels, and ensure data packets are transmitted only through authorized tunnels, using an external server to manage tunnel generation and access control, thereby blocking unauthorized data packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARP spoofing is used to block unauthorized terminals, then network access control is improved, but network load increases and security vulnerabilities arise
Solution Approach 1:
The patent introduces a tunnel as an intermediary mechanism between the terminal and network. Instead of directly blocking unauthorized access through ARP spoofing, the system establishes a secure tunnel that mediates all data packet transmissions. The tunnel acts as a controlled passage where only authorized traffic can pass, eliminating the need for harmful ARP spoofing while maintaining access control reliability.
Solution Approach 2:
The patent replaces the mechanical ARP spoofing mechanism with a tunnel-based virtual private network approach. Rather than manipulating network layer protocols to block access, the system uses encryption and tunneling mechanisms to secure data transmission. This substitution eliminates the harmful effects of ARP spoofing while providing more robust security through cryptographic protection.
2Reliability
If firewall is used to control data packet flow, then data transmission security is improved, but connection generation capability is reduced
Solution Approach 1:
The patent applies preliminary action by establishing a tunnel before any data transmission occurs. The tunnel is set up in advance through authentication and key exchange, creating a secure pathway that enables subsequent data communications. This preliminary tunnel establishment allows the firewall to focus solely on securing existing connections rather than attempting to generate new ones, resolving the contradiction between security and connection capability.
3Reliability
If VPN is used to ensure data integrity and confidentiality, then data security is improved, but data packet flow management becomes complex
Solution Approach 1:
The patent segments the network access control function into distinct components: authentication, tunnel establishment, and data packet filtering. By dividing these functions, the system manages complexity more effectively. The tunnel handles encryption and confidentiality, while separate access control mechanisms handle packet flow management, making the overall system more manageable despite maintaining high security standards.
Data Source
AI summary
A node includes: a communication circuit; a processor operatively connected to the communication circuit; and a memory operatively connected to the processor and storing a target application and an access control application, wherein the memory stores instructions that when executed by the processor, cause the node to: detect a network access event of the target application to a destination network through the access control application, identify whether a tunnel corresponding to identification information of the target application and the destination network and authorized by an external server exists, transmit a data packet of the target application through the authorized tunnel using the communication circuit, when the authorized tunnel exists, and drop the data packet of the target application, when the authorized tunnel does not exist.


