Network Access Control via Authorized Tunnel for Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control technologies, such as ARP spoofing and VPNs, are vulnerable to security breaches, particularly at the application and transport layers, and face challenges in managing data packet flow effectively, with ARP spoofing putting a load on the network and VPNs being susceptible to post-tunnel data packet management issues.

Innovation Solution

A system and method that utilize a node with a communication circuit, processor, and memory to detect network access events, identify authorized tunnels, and ensure data packets are transmitted only through authorized tunnels, using an external server to manage tunnel generation and access control, thereby blocking unauthorized data packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ARP spoofing is used to block unauthorized terminals, then network access control is improved, but network load increases and security vulnerabilities arise

Engineering Contradiction:
Improvenetwork access controlVSAvoidnetwork load and security vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a tunnel as an intermediary mechanism between the terminal and network. Instead of directly blocking unauthorized access through ARP spoofing, the system establishes a secure tunnel that mediates all data packet transmissions. The tunnel acts as a controlled passage where only authorized traffic can pass, eliminating the need for harmful ARP spoofing while maintaining access control reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical ARP spoofing mechanism with a tunnel-based virtual private network approach. Rather than manipulating network layer protocols to block access, the system uses encryption and tunneling mechanisms to secure data transmission. This substitution eliminates the harmful effects of ARP spoofing while providing more robust security through cryptographic protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If firewall is used to control data packet flow, then data transmission security is improved, but connection generation capability is reduced

Engineering Contradiction:
Improvedata transmission securityVSAvoidconnection generation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by establishing a tunnel before any data transmission occurs. The tunnel is set up in advance through authentication and key exchange, creating a secure pathway that enables subsequent data communications. This preliminary tunnel establishment allows the firewall to focus solely on securing existing connections rather than attempting to generate new ones, resolving the contradiction between security and connection capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If VPN is used to ensure data integrity and confidentiality, then data security is improved, but data packet flow management becomes complex

Engineering Contradiction:
Improvedata integrity and confidentialityVSAvoiddata packet flow management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network access control function into distinct components: authentication, tunnel establishment, and data packet filtering. By dividing these functions, the system manages complexity more effectively. The tunnel handles encryption and confidentiality, while separate access control mechanisms handle packet flow management, making the overall system more manageable despite maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11271777B2System for controlling network access of terminal based on tunnel and method thereof
Publication Date: 2022.03.08 PRIBIT TECH INC
  • US11271777B2 patent drawing
  • US11271777B2 patent drawing
  • US11271777B2 patent drawing

AI summary

A node includes: a communication circuit; a processor operatively connected to the communication circuit; and a memory operatively connected to the processor and storing a target application and an access control application, wherein the memory stores instructions that when executed by the processor, cause the node to: detect a network access event of the target application to a destination network through the access control application, identify whether a tunnel corresponding to identification information of the target application and the destination network and authorized by an external server exists, transmit a data packet of the target application through the authorized tunnel using the communication circuit, when the authorized tunnel exists, and drop the data packet of the target application, when the authorized tunnel does not exist.