Portable Authentication Module for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in managing access to network management areas, particularly when a large number of maintenance terminals and ports are involved, leading to increased operational complexity and potential security breaches due to the need for manual registration of MAC addresses and management of security keys.

Innovation Solution

A network system that employs a portable connection device holding authentication information, allowing the network device to authenticate terminal devices based on pre-set connection information, reducing the need for manual registration and simplifying access management by using a portable module to securely connect maintenance terminals to specific network management areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual registration of MAC addresses and security keys is implemented for each maintenance terminal and port, then network security is improved, but device complexity and operational complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A portable connection device is introduced as an intermediary between the maintenance terminal and the operational switch. This device holds authentication information and performs authentication automatically, eliminating the need for manual MAC address registration and security key management while maintaining network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The portable connection device performs self-authentication by automatically presenting its authentication information to the operational switch. This eliminates the need for manual intervention in the authentication process, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual registration of MAC addresses for each maintenance terminal is required, then access control security is improved, but the time and effort required for setup and management increases

Engineering Contradiction:
Improveaccess control securityVSAvoidsetup and management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication information is pre-loaded into the portable connection device before it is needed. This preliminary setup eliminates the need for time-consuming manual MAC address registration and security key distribution at the time of connection, while still ensuring secure access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The portable connection device contains copied authentication information that can be automatically presented to multiple operational switches without requiring unique manual configuration for each connection. This reduces setup and management time while maintaining access control security.

Inventive Principle:
Principle #26Copying

3Reliability

If security locks with security keys are provided in individual ports, then physical security is improved, but ease of operation deteriorates due to key management complexity

Engineering Contradiction:
Improvephysical securityVSAvoidkey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mechanical security lock and physical key system is replaced with an electronic authentication system. The portable connection device performs electronic authentication with the operational switch, eliminating the need for physical security locks and key management while maintaining security through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9548974B2Network system, network device and connection control method
Publication Date: 2017.01.17 FSAS TECH INC
  • US9548974B2 patent drawing
  • US9548974B2 patent drawing
  • US9548974B2 patent drawing

AI summary

A network system includes: a network device; and a portable connection device capable of connecting thereto a terminal device which accesses the network device, where the portable connection device holds authentication information related to the connection between the network device and the terminal device, the authentication information being previously set. Here, the network device includes a processor, and the processor acquires the authentication information held in the portable connection device according to the connection of the portable connection device to the network device, acquires identification information on the terminal device from the terminal device according to the connection of the terminal device to the portable connection device, and compares the acquired authentication information with the identification information on the terminal device and device information on the network device to determine whether or not the access from the terminal device is allowed.