Network Device Access Control for Shared Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless digital networks, client devices can discover and communicate with shared devices without authorization, leading to unauthorized access, which existing technologies fail to effectively prevent.

Innovation Solution

A network device identifies and blocks unauthorized communication between client and shared devices by ensuring that only authorized client devices receive the IP address of shared devices, using a policy manager and data repository to enforce access control policies and terminate unauthorized connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If client devices can discover shared devices directly without intermediate network device approval, then device discovery capability is improved, but network security deteriorates due to unauthorized access

Engineering Contradiction:
Improvedevice discovery capabilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediate network device that acts as a mediator between client devices and shared devices. This intermediary monitors and controls communication, allowing legitimate device discovery while blocking unauthorized access attempts, thus resolving the contradiction between discovery capability and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the intermediate network device monitors communication patterns, identifies unauthorized access attempts, and responds by blocking such communications. This feedback loop maintains security while allowing legitimate device discovery to proceed

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If intermediate network devices present shared devices to client devices, then network security is improved, but device discovery versatility deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice discovery versatility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic control where the intermediate network device adaptively manages device presentation based on authorization status. Legitimate shared devices are presented to authorized clients, while unauthorized access attempts are blocked, achieving both security and versatility through dynamic rather than static control

Inventive Principle:
Principle #15Dynamics

3Speed

If client devices communicate directly with shared devices without authorization, then communication speed is improved, but network integrity deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidnetwork integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary authorization checks before allowing direct communication between client and shared devices. By pre-establishing authorization status and controlling IP address distribution, the system enables fast communication for authorized devices while preventing unauthorized access, thus maintaining both speed and integrity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9894070B2Method and system for controlling access to shared devices
Publication Date: 2018.02.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9894070B2 patent drawing
  • US9894070B2 patent drawing
  • US9894070B2 patent drawing

AI summary

A non-transitory computer readable medium includes computer readable program code including instructions for snooping a message from a client device addressed to a particular IP address corresponding to a shared device; determining whether the client device has authorization to access the shared device; responsive to determining that the client device does not have authorization to access the shared device, refraining from forwarding the message to the particular IP address; and responsive to determining that the client device has authorization to access the shared device, forwarding the message to the particular IP address.