Network Intermediary Access Control for Unmanaged Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access-control techniques face challenges in enforcing policies across various devices and physical spaces, as some devices cannot execute software, administrators may be unwilling or unable to install endpoint security, and users can circumvent controls by uninstalling software or tampering with access-control systems, especially in shared machines where proper user identification is unfeasible.

Innovation Solution

The system identifies and matches devices within a physical space, establishing lists of controlled and monitoring devices to enforce access-control policies by determining physical locations and monitoring user activity, using self-propelled monitoring devices to map boundaries and track device locations over time, enabling security actions based on observed activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access-control software is installed on devices, then access-control policies can be enforced, but devices that cannot execute software or where administrators are unwilling to install software become uncontrollable

Engineering Contradiction:
Improveaccess-control policy enforcementVSAvoidcompatibility with diverse devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces network infrastructure components (routers, switches, firewalls) as intermediaries between users and controlled devices. These intermediaries enforce access-control policies without requiring software installation on the controlled devices themselves. The system proxies authentication and authorization decisions through the network infrastructure, allowing policy enforcement on devices that cannot or will not run access-control software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access-control software is installed on devices, then policy enforcement is possible, but users can circumvent controls by uninstalling software, killing processes, or tampering with the access-control system

Engineering Contradiction:
Improveaccess-control policy enforcementVSAvoidsoftware tampering and circumvention
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By moving the access-control logic to network infrastructure intermediaries rather than client devices, the system eliminates the vulnerability of client-side software tampering. The intermediary components control access at the network level, making it impossible for users to circumvent controls through local software manipulation, process termination, or system tampering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/software-based access-control mechanism (installed applications and processes) with a network-based infrastructure system. This substitution moves the control mechanism from the vulnerable software layer to the network infrastructure layer, where it cannot be easily tampered with or circumvented by local user actions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If access-control software is installed on shared machines, then policy enforcement is possible, but proper user identification becomes unfeasible

Engineering Contradiction:
Improveaccess-control policy enforcementVSAvoiduser identification capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The network infrastructure intermediary acts as an authentication gateway between users and shared resources. It maintains separate authentication contexts for different users accessing shared machines, enabling proper user identification and policy enforcement even when multiple users are physically present at the same location. The intermediary proxies authentication decisions, allowing the system to distinguish between different users based on their authentication credentials rather than physical presence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10462184B1Systems and methods for enforcing access-control policies in an arbitrary physical space
Publication Date: 2019.10.29 GEN DIGITAL INC
  • US10462184B1 patent drawing
  • US10462184B1 patent drawing
  • US10462184B1 patent drawing

AI summary

The disclosed computer-implemented method for enforcing access-control policies in an arbitrary physical space may include (i) identifying a collection of devices that are located within a predetermined physical space, (ii) determining the physical location of each device in the collection of devices, (iii) establishing, based on the collection of devices, (a) a list of controlled devices that are subject to an access-control policy and (b) a list of monitoring devices that are capable of monitoring user activity within a physical proximity, (iv) matching each controlled device with at least one monitoring device that is capable of monitoring user activity within physical proximity to the controlled device, and (v) monitoring, for each controlled device and by each monitoring device matched to the controlled device, user activity within proximity to the controlled device. Various other methods, systems, and computer-readable media are also disclosed.