Network Access Gateway Walled Garden Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of networked devices increases, so does the risk of destructive or unauthorized access to networked devices, necessitating methods to detect and limit abnormal or abusive use of network resources while maintaining user access and service levels.

Innovation Solution

Implementing a network access gateway that uses firewall rule technology to recognize clients by identity or group membership, creating a 'walled garden' with specific access rules to confine network access, allowing selective content access and notifying users of potential infections while reducing the impact of virus and worm infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network client is completely removed from network access due to abnormal or abusive behavior, then network security is improved, but user service level and business etiquette are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoiduser service level
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network access into different zones or regions. Instead of completely isolating a problematic client, the system creates a restricted zone that allows the client to access only specific network resources (such as security patches or informational sites) while blocking access to other resources. This segmentation enables differentiated access levels based on client behavior.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing different access qualities to different clients based on their behavior. Problematic clients receive limited access to specific resources, while legitimate clients maintain full access. This allows the system to address security concerns without uniformly degrading service for all users.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If network access is constrained to a limited region, then abnormal client impact is reduced, but client access to network resources is worsened

Engineering Contradiction:
Improveabnormal client impactVSAvoidclient access to network resources
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism (the network access gateway with walled garden functionality) that mediates between the problematic client and the network resources. This intermediary selectively permits certain types of traffic while blocking others, allowing the client to access helpful resources like security patches while preventing access to harmful or abusive targets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the harmful effect of a compromised client into a beneficial outcome by using the client's abnormal behavior as a trigger to provide targeted assistance. Instead of simply blocking all access, the system identifies the problem and provides selective access to resources that can help resolve the issue, such as security updates or diagnostic information.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If firewall rules are configured to recognize clients by identity or group membership, then network access control is improved, but system complexity is worsened

Engineering Contradiction:
Improvenetwork access controlVSAvoidfirewall rule configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal client identification mechanism that can recognize clients by multiple attributes (identity, group membership, behavior patterns) through a single integrated system. The walled garden gateway provides multi-functional capabilities including access control, client classification, and selective routing, reducing the need for multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8543710B2Method and system for controlling network access
Publication Date: 2013.09.24 NETSKOPE INC
  • US8543710B2 patent drawing
  • US8543710B2 patent drawing

AI summary

Systems and methods intended to control a network devices access to a network are disclosed. Embodiments of the current invention expose a method for confining a network client's network access to a specific logical region of the network. A network communication may be received and the client that originated this communication determined. This client is associated with a set of rules or walled garden that specifies the access allowed by that client. The destination of the communication may also be determined and if the destination is allowed by the set of rules associated with the client and access to the destination allowed if access to the destination is allowed by the set of rules.