Network Device Maximum Device Access Restriction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in detecting unauthorized access when multiple devices use the same set of authentication credentials, making it difficult to determine if a user is using multiple devices or if the credentials have been compromised.

Innovation Solution

Implementing a maximum device restriction mechanism within network devices, where the number of devices allowed to access the network using a single set of credentials is limited, allowing only up to a defined quantity before denying further access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multiple devices are allowed to access the network using the same authentication credentials, then network accessibility and user convenience are improved, but network security and the ability to detect unauthorized access deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter of device quantity from unlimited to limited by implementing a maximum device restriction mechanism. The network device monitors and counts the number of devices using the same authentication credentials, and when this count exceeds a predetermined threshold, access is denied. This parameter change resolves the contradiction by maintaining ease of operation for legitimate users while improving network security through automated limitation of concurrent device access.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If authentication credentials are shared across multiple devices, then user convenience is improved, but the ability to detect credential compromise deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidcredential compromise detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the network device continuously monitors and counts the number of devices successfully authenticating with the same credentials. This count information is fed back to the authentication process, and when the predetermined threshold is exceeded, the system automatically denies further access. This feedback loop enables detection of potential credential compromise while maintaining convenience for legitimate multi-device usage within the allowed limit.

Inventive Principle:
Principle #23Feedback

3Reliability

If a maximum device restriction is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the network device automatically performs the functions of monitoring, counting, and enforcing device limits without requiring external intervention. The system autonomously tracks the number of devices using each set of credentials, compares this count against the predetermined threshold, and automatically denies access when the limit is exceeded. This self-service approach improves network security while minimizing the added complexity by eliminating the need for manual monitoring or external authentication servers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11811765B1Maximum device access restriction at authenticator level
Publication Date: 2023.11.07 JUNIPER NETWORKS INC
  • US11811765B1 patent drawing
  • US11811765B1 patent drawing
  • US11811765B1 patent drawing

AI summary

A network device may receive a request to access a network from a client device. The network device may determine that the client device is authenticated based on a set of authentication credentials obtained for the client device. The network device may determine, based on the client device being authenticated, that a quantity of devices currently accessing the network using the set of authentication credentials is equal to a maximum quantity of devices permitted to access the network using the set of authentication credentials. The network device may deny the client device access to the network based on the quantity of devices being equal to the maximum quantity of device.