Network Security Policy Enforcement via Context-Aware Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting private networks from information leakage and unauthorized data transfer are inadequate, as they either restrict access too broadly, reducing productivity or fail to differentiate between sensitive and non-sensitive information, and do not effectively verify the environment or device behavior.

Innovation Solution

A method employing a Security Manager Module and client agents that analyze data transportation according to communication protocols, enforcing security policies to allow or block data transfers based on user rights, device behavior, and environmental context, while allowing selective access and transfer of files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to valuable information and external storage devices is prevented using physical or software techniques, then network security is improved, but user productivity is reduced

Engineering Contradiction:
Improvenetwork securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing fine-grained access control that differentiates between various types of information and devices. Instead of uniform blocking, the system applies security policies selectively to specific files, folders, and external devices based on their sensitivity and the user's role, allowing legitimate work while preventing data leakage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the information space into classified categories (public, internal, confidential, secret) and applies different access control policies to each segment. This segmentation allows users to access appropriate information for their work while preventing unauthorized transfer of sensitive data to external devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access to external devices is completely blocked, then information leakage is prevented, but legitimate device functionality is restricted

Engineering Contradiction:
Improveinformation leakage preventionVSAvoiddevice access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where security policies are applied in real-time based on the current context, including the type of external device, the user's actions, and the sensitivity of the information being accessed. This dynamic approach allows legitimate device functionality while preventing information leakage through contextual policy enforcement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor device connections and user actions, then apply appropriate security policies based on the detected context. The system provides feedback to users about allowed or blocked operations and adjusts access control based on ongoing monitoring of device behavior and information transfer patterns.

Inventive Principle:
Principle #23Feedback

3Device complexity

If broad access control policies are applied to all information, then security is simplified to enforce, but differentiation between sensitive and non-sensitive information is lost

Engineering Contradiction:
Improvesecurity policy enforcement complexityVSAvoidinformation sensitivity differentiation
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by pre-classifying information into sensitivity levels and pre-defining security policies for each classification. This preliminary categorization simplifies enforcement while maintaining precise differentiation, as the system only needs to match the current operation against predefined policies rather than making complex real-time decisions about information sensitivity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8544062B2Method and system for improving computer network security
Publication Date: 2013.09.24 SUPERCOM IP LLC
  • US8544062B2 patent drawing
  • US8544062B2 patent drawing
  • US8544062B2 patent drawing

AI summary

Computers connected to a private network are monitored and controlled through the use of a client agent that operates in association with the computer and a server client that establishing security parameters, privileges and authorizations for the computer. The invention can prevent access to certain devices according to an active security policy. Any activity of the computer, such as a request to transfer data to an external device, access a particular file, etc. is monitored and controlled by the client agent. No operations or procedures are allowed by the computer inconsistent with the active security policy. The security policy may be set by the administrator of the private network according to the user rights and position in the organization.