Network Device Validation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to preemptively identify and block malicious network devices in large networks, allowing unauthorized access and data leakage, as they detect malicious activity only after it has occurred, limiting their ability to provide information security and control data access.

Innovation Solution

The system identifies and blocks potentially malicious network devices by comparing device information and location data from logs with actual switch-provided information, activates temporary port leases based on device authentication status, and enables port authentication for discrepancies, thereby controlling access and preventing malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection systems are used to identify malicious network devices, then detection capability is provided, but detection occurs only after malicious activity has already happened, allowing data leakage and unauthorized access

Engineering Contradiction:
Improveinformation securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by validating device information (MAC address, device type, location) against authorized lists before devices can perform malicious activities. This preemptive validation prevents unauthorized access and data leakage before they occur, rather than detecting them after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by blocking suspicious devices from accessing the network before they can execute malicious activities. The access control system proactively prevents unauthorized devices from connecting, stopping potential data exfiltration or malware introduction before it happens.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If the system blocks all unauthorized devices to prevent malicious activities, then network security is improved, but legitimate devices may also be blocked causing network disruption

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses feedback mechanisms by continuously monitoring device information and comparing it against authorized lists. When a device's information matches the authorized criteria, access is granted; when it doesn't match, access is blocked. This feedback loop ensures legitimate devices operate normally while unauthorized devices are prevented from accessing the network.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies local quality by validating specific device attributes (MAC address, device type, location) individually against corresponding authorized lists. This granular validation approach allows the system to precisely identify and authorize legitimate devices while blocking only unauthorized ones, avoiding unnecessary disruption to legitimate network operations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11190515B2Network device information validation for access control and information security
Publication Date: 2021.11.30 BANK OF AMERICA CORP
  • US11190515B2 patent drawing
  • US11190515B2 patent drawing
  • US11190515B2 patent drawing

AI summary

A system that includes a threat management server configured to store a device log identifying device information for endpoint devices that have passed authentication. The threat management server is configured to determine that first device information for an endpoint device obtained from a switch and second device information for the endpoint device from the device log file do not match, and, in response, block the endpoint device from accessing a network. The switch is operably coupled to the threat management server and configured to collect the first device information for the endpoint device and send it to the threat management engine.