Network Access Zones for Secure Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures are inadequate in addressing sophisticated security attacks, as they often focus solely on user authentication and neglect the security context of client devices, allowing infected devices to compromise the network.

Innovation Solution

Implementing a method that establishes multiple access zones in a network based on client device security assessments, with dynamic reassignment and traffic filtering to isolate and remediate potentially compromised devices, using a centralized access controller and agent programs to manage device access and traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional user authentication methods are used, then user access control is simplified, but network security is compromised because infected devices can still access the network

Engineering Contradiction:
Improveuser authenticationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network is segmented into multiple access zones (e.g., untrusted zone, semi-trusted zone, trusted zone) based on security assessments. Devices are dynamically assigned to different zones according to their security posture, allowing granular control over network access while maintaining overall security. This resolves the contradiction by enabling both ease of authentication and enhanced security through zone-based isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security assessments are performed in advance before granting full network access. The system proactively evaluates device security posture (virus definitions, patches, security software) and assigns devices to appropriate access zones beforehand. This preliminary security verification ensures that infected devices cannot compromise the network while maintaining smooth authentication for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict security filtering is applied to all devices, then network security is improved, but network traffic efficiency deteriorates due to excessive filtering overhead

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork traffic efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Different security filtering levels are applied to different access zones based on local security requirements. The untrusted zone receives strict filtering, the semi-trusted zone receives moderate filtering, and the trusted zone receives minimal filtering. This localized approach maintains high security where needed while preserving network traffic efficiency in trusted areas, resolving the contradiction between security and productivity.

Inventive Principle:
Principle #3Local quality

3Reliability

If dynamic access zone reassignment is implemented, then network security responsiveness is improved, but system complexity increases due to continuous monitoring and reassignment

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors device security posture through agents that report status changes (virus updates, patch installations, security software status). Based on this feedback, the access controller dynamically reassesses device security and reassigns devices to appropriate access zones. This feedback mechanism enables responsive security management without requiring complete system redesign, balancing security responsiveness with manageable complexity.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If comprehensive security assessments are performed on all devices, then detection accuracy of infected devices is improved, but processing time increases due to extensive security checks

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security assessments selectively based on device characteristics, access zone requirements, and security event triggers. Not all devices undergo full security checks at all times - assessments are performed partially or excessively only when necessary (e.g., when security violations are detected, when devices move between zones, or for high-risk devices). This approach maintains high detection accuracy for critical cases while reducing average processing time for routine operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8707395B2Technique for providing secure network access
Publication Date: 2014.04.22 PULSELINK SYSTEMS LLC
  • US8707395B2 patent drawing
  • US8707395B2 patent drawing
  • US8707395B2 patent drawing

AI summary

A technique for providing secure network access is disclosed. In one particular exemplary embodiment, the technique may be realized as a method for providing secure network access. The method may comprise establishing a plurality of access zones in a network, wherein client devices assigned to different access zones have different access privileges and are isolated from one another. The method may also comprise assigning a client device to one of the plurality of access zones based on an assessment of a security context associated with the client device and a connection of the client device to the network.