Network Device Location Validation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems are unable to preemptively identify and block malicious network devices, allowing unauthorized access and data leakage, as they typically detect malicious activity after it has occurred, limiting their ability to provide effective information security and data access control.

Innovation Solution

The system identifies and blocks potentially malicious network devices by comparing device information and location data from device logs with actual switch data, activates temporary port leases based on device authentication status, and enables port authentication to monitor and control access, thereby preventing malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection systems are used to identify malicious network devices, then detection capability is provided, but detection occurs only after malicious activity has already taken place, allowing data leakage and unauthorized access

Engineering Contradiction:
Improvenetwork securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by validating device information (MAC address, device type, location) against authorized device logs before allowing network access. This preemptive validation prevents malicious devices from connecting in the first place, rather than detecting them after malicious activity occurs. The system checks device credentials, compares actual switch data with logged information, and blocks unauthorized devices before they can perform malicious activities, thus resolving the contradiction between reliability and response time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system implements comprehensive device validation and monitoring, then network security is improved, but system complexity increases due to additional validation steps and data comparison processes

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary validation mechanism that acts as a mediator between network devices and the core network infrastructure. The validation system compares device information through switches against authorized device logs, using this intermediary layer to filter and control access without requiring complex changes to the entire network architecture. This intermediary approach maintains security while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates and maintains copies of authorized device information in device logs, which are then used for validation comparisons. By working with copied device data (MAC addresses, device types, locations) rather than directly managing all network device complexities, the system simplifies the validation process while maintaining comprehensive security checks.

Inventive Principle:
Principle #26Copying

3Reliability

If the system blocks devices with information discrepancies, then unauthorized access is prevented, but legitimate devices may be incorrectly blocked, affecting network accessibility

Engineering Contradiction:
Improveaccess controlVSAvoidnetwork accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where device information is continuously validated against authorized logs, and blocking decisions are based on discrepancies detected through this feedback loop. The system provides feedback by comparing actual device data with authorized device logs and only blocks devices when genuine discrepancies are found, allowing legitimate devices to pass validation seamlessly while preventing unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10375076B2Network device location information validation for access control and information security
Publication Date: 2019.08.06 BANK OF AMERICA CORP
  • US10375076B2 patent drawing
  • US10375076B2 patent drawing
  • US10375076B2 patent drawing

AI summary

A system that includes a threat management server configured to store a device log identifying location information for endpoint devices that have passed authentication. The threat management server is configured to identify an endpoint device from the device log file and to identify a switch connected the endpoint device. The threat management server is further configured to send a location information request to the switch requesting location information for the endpoint device. The threat management server is configured to compare the received information to the information in the device log file. The threat management server is configured to block the endpoint device from accessing a communications network in response to determining the received location information does not match the information in the device log file.