Dynamic Network Security States for Layered Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network security measures are static and unable to dynamically adjust protection levels in response to user needs or system requirements, leaving networks vulnerable to attacks.

Innovation Solution

A computer security mechanism that employs multiple security states with transitions based on specified conditions or events, allowing successively increased levels of network access, including disabling all network access initially, then allowing outbound connections, local inbound connections, remote connections, and finally authenticated connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static firewalls and security measures are used, then network security is maintained at a fixed level, but the system cannot dynamically adapt to changing user needs or attack conditions

Engineering Contradiction:
Improvedynamic adaptabilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic security states that can transition between different levels of network access based on real-time conditions. The system moves from a static firewall approach to a dynamic state machine that adjusts security parameters automatically, allowing the network to adapt its security posture in response to user actions, network conditions, and detected threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters by transitioning between multiple defined security states (e.g., state 1: no network access, state 2: outbound only, state 3: local inbound allowed, state 4: remote inbound allowed). Each state is characterized by different parameter settings for network access control, enabling flexible adaptation without compromising security reliability.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple security states with transitions are implemented, then dynamic security adjustment is achieved, but the system complexity increases

Engineering Contradiction:
Improvesecurity flexibilityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security mechanism is segmented into discrete, manageable security states (state 1 through state 4 in the patent) with clearly defined transition conditions. This segmentation breaks down the complex security control into manageable components, making the system more implementable while maintaining flexibility. Each state is a distinct configuration with specific access rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses a state machine approach where security transitions are triggered by specific events or conditions. This dynamic structure provides flexibility through multiple states while managing complexity through event-driven transitions rather than continuous monitoring and adjustment.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If network access is completely disabled, then security against unauthorized access is maximized, but legitimate user needs for network communication are blocked

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidnetwork accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically adjusts network access based on user needs and security conditions. Instead of a fixed blocked state, the system can transition to allowed states when legitimate communication is detected or authorized, balancing security with usability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security system incorporates feedback mechanisms that monitor network activity and user actions. When legitimate communication patterns are detected, the system responds by transitioning to more permissive security states, allowing network access while maintaining protection against unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250365285A1Systems and methods for computer network security
Publication Date: 2025.11.27 CHIEN DANIEL
  • US20250365285A1 patent drawing
  • US20250365285A1 patent drawing
  • US20250365285A1 patent drawing

AI summary

Techniques and systems for computer network security are described. One example system includes a computer security mechanism based on multiple security states that each allow successively increased levels of network access, where transitions between the security states occur in response to specified conditions or events. An example system starts (e.g., boots, initializes, powers up) in a first state in which no network communication is allowed. In response to an event such as a user starting a Web browser or other approved program, the system transitions into a second state, in which only outbound network communication is allowed. Thus, in the second state the Web browser can make an outbound request for information but any inbound connection requests will be rejected. In response to other events, the system transitions to security states that allow successively higher levels of network communication.