Network Management Server for Unauthorized Device Cutoff

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing information processing devices connected to a network struggle to distinguish between devices with the same identifier, making it difficult to determine whether a device is authorized or unauthorized, especially when unauthorized devices spoof the identifier of authorized devices.

Innovation Solution

A management server and communication cutoff device system that acquires and accumulates device and segment identifying information to determine if communication cutoff is required, and notifies a communication cutoff device to disconnect unauthorized devices, using ARP spoofing and MAC address manipulation to manage network segments effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a whitelist or blacklist method is used to manage information processing devices by recording their identifiers, then it is simple to implement and operate, but it becomes impossible to distinguish between multiple devices having the same identifier, making authorization determination difficult

Engineering Contradiction:
Improvesimplicity of managementVSAvoiddevice identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the identifier into two distinct parts: a common identifier (shared by multiple devices) and a unique identifier (specific to each device). This segmentation allows the system to first group devices by common identifier and then differentiate them using unique identifiers, resolving the contradiction between simple management and accurate identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds an additional dimension to device identification by introducing unique identifiers beyond the common identifier. Instead of relying solely on a single identifier dimension, the system now operates in a two-dimensional identifier space, enabling precise distinction between devices that share the same common identifier.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple devices with the same identifier are connected to the network, then resource sharing and flexibility are improved, but the ability to determine whether a specific device is authorized or unauthorized deteriorates

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidauthorization determination reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

By segmenting the identifier system into common and unique components, the patent maintains network flexibility (devices can share common identifiers) while ensuring authorization reliability (each device is uniquely identified for accurate authorization checks).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses the unique identifier as feedback information to distinguish between multiple devices sharing the same common identifier. When an ARP request is received, the system retrieves the unique identifier corresponding to the common identifier and uses it to accurately determine whether the specific device is authorized, preventing unauthorized access while allowing legitimate devices to communicate.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If ARP spoofing is used to establish connections for not-yet-authorized devices, then connection establishment becomes easier, but the ability to distinguish between authorized and unauthorized devices deteriorates

Engineering Contradiction:
Improveconnection establishment easeVSAvoiddevice distinction difficulty
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary action by pre-registering both common identifiers and unique identifiers for authorized devices in the management server before they connect to the network. When devices attempt to connect via ARP spoofing, the system can immediately retrieve the pre-registered unique identifier and verify authorization, making detection of unauthorized devices straightforward despite the ease of connection establishment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9444821B2Management server, communication cutoff device and information processing system
Publication Date: 2016.09.13 PFU LTD
  • US9444821B2 patent drawing
  • US9444821B2 patent drawing
  • US9444821B2 patent drawing

AI summary

An inspection system 1 having a plurality of network segments 2 includes: a management information acquiring unit 34 which acquires a node ID that a node 90 belonging to the network segment 2 can be identified and a segment ID that the network segment 2 to which the node 90 belongs can be identified; a management information accumulating unit 35 which accumulates the acquired node ID and segment ID in the way of being associated with each other; a cutoff determining unit 36 which determines whether the cutoff of the communications of the node 90 specified by the accumulated node ID and segment ID is required or not; and a communication cutoff unit 21 which cuts off the communications of the node 90 specified by the node ID in the case of determining that the cutoff of the communications of the node 90 is required.