Network Locality Workflow Triggering for Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internal network devices, such as laptops and smartphones, can be lost or stolen, potentially allowing malicious users to access internal network resources via security credentials stored on these devices, leading to data exfiltration and security breaches, as existing security measures are inadequate in preventing misuse when these devices connect to external networks.
Innovation Solution
Implementing a system that uses network locality to automatically disable privileged access for internal network devices when they connect to external networks by configuring devices to periodically communicate with hosts on external or internal networks, where communication failure or success triggers access disabling mechanisms, such as the internal and external lockout services, to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices are allowed to connect to external networks for operational flexibility, then adaptability is improved, but security is worsened due to potential data exfiltration and unauthorized access
Solution Approach 1:
The system continuously monitors network connectivity status by attempting to resolve domain names and establish connections. When a device connects to an external network, the system detects this change through failed internal network resolutions and triggers appropriate security responses, such as disabling privileged access or notifying administrators.
Solution Approach 2:
The system introduces an intermediary security service that acts as a broker between network connectivity and security policies. This service monitors connectivity status and mediates access control decisions, allowing the system to adapt connectivity while maintaining security through policy enforcement.
2Ease of operation
If security credentials are stored on mobile devices for convenient access, then ease of operation is improved, but reliability is worsened due to potential loss or theft of devices
Solution Approach 1:
The system dynamically adjusts security credentials and access rights based on real-time network connectivity detection. When a device is lost or stolen and connects to an external network, the system automatically revokes credentials or disables access, transforming static security into a dynamic response that adapts to the device's location and network status.
Solution Approach 2:
The system performs preliminary security actions by pre-configuring monitoring mechanisms that automatically detect when a device connects to external networks. This allows the system to take preventive security measures before actual data exfiltration or unauthorized access can occur.
3Object-affected harmful factors
If automatic security responses are implemented when external network connection is detected, then security is improved, but device complexity increases due to additional monitoring and control mechanisms
Solution Approach 1:
The system implements a universal security service that handles multiple security functions through a single unified mechanism. This service monitors network connectivity, detects external network attachments, and enforces security policies, consolidating what could be multiple separate security systems into one multi-functional component.
Data Source
AI summary
Disclosed are various embodiments for using network locality to automatically trigger arbitrary workflows either by assertion or implication. In one embodiment, a communication is received from a client device via an external network host connected to an external network. The client device is configured to initiate the communication to the external network host on a repeated basis. The external network host is unreachable from an internal network. Access by the client device to at least one resource on the internal network is then disabled in response to receiving the communication.


