Network Quarantine System for Secure Client Terminal Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network quarantine systems face challenges in securely connecting client terminals to a LAN, as infected terminals can spread viruses, and inadequate password settings can lead to hacker intrusions, posing risks to both servers and other terminals, especially when managing a large number of terminals without burdening network administrators.

Innovation Solution

A quarantine system that authenticates client terminals using common and user certificates, performing security checks and measures through a quarantine network before allowing connection to the user network, ensuring only secure terminals access the primary network, thereby preventing virus spread and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a client terminal is automatically connected to a LAN when it starts, then connection efficiency is improved, but virus spread and security risks increase

Engineering Contradiction:
Improveconnection speedVSAvoidvirus spread
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security checks and virus scanning on client terminals before allowing them to connect to the LAN. The authentication apparatus checks whether the terminal has completed required security measures (such as virus scanning and security patch installation) before permitting network access, thereby preventing virus spread while maintaining efficient connection for compliant terminals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication apparatus acts as an intermediary between client terminals and the LAN. It mediates the connection process by verifying security status, managing certificates, and controlling access rights. This intermediary layer enables security checks without blocking legitimate terminals, thus balancing security and connection efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security checks are performed on all client terminals, then network security is improved, but administrative burden and processing time increase

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables client terminals to perform self-authentication and self-compliance verification. Terminals automatically present their security status, certificates, and compliance information to the authentication apparatus, which processes these submissions automatically without requiring manual administrative intervention for each terminal.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication apparatus provides multiple functions including virus scanning coordination, security patch verification, certificate management, and access control authorization. By consolidating these functions into a single apparatus, the system reduces overall system complexity while maintaining comprehensive security checks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If infected terminals are allowed to connect to the LAN, then network accessibility is improved, but harm to servers and other terminals increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddamage to servers and terminals
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system takes preliminary anti-action by detecting and preventing infected or non-compliant terminals from connecting to the LAN before they can cause harm. The authentication apparatus identifies terminals that have not completed required security measures (such as virus scanning or patch installation) and blocks their access, thereby preventing potential damage to servers and other terminals while allowing clean terminals to access the network.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8359464B2Quarantine method and system
Publication Date: 2013.01.22 KYNDRYL INC
  • US8359464B2 patent drawing
  • US8359464B2 patent drawing
  • US8359464B2 patent drawing

AI summary

A quarantine method and system for allowing a client terminal to connect to a user network. An authentication apparatus recognizes that a communication means of the client terminal has been activated. The authentication apparatus is connected to a quarantine network, to the user network, and to the client terminal. The client terminal is permitted to connect to the quarantine network by confirming a common certificate for the client terminal followed by storing the common certificate in the client terminal. The client terminal is security checked to determine whether each check item of a plurality of check items has a violation. For each check item having a violation, a security measure is performed to improve the check item with respect to the violation. The client terminal is allowed to connect to the user network by confirming a user certificate for the client terminal followed by storing the user certificate in the client terminal.