Portable System Internet Access Control via Network Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network access for a large number of users across various network resources becomes complex when users' authorization changes, such as when employees leave or join a company, and portable systems can access the internet before connecting to the enterprise VPN, posing risks of malware infection and data leakage.

Innovation Solution

A network monitoring system that blocks internet access for portable systems until they are properly connected to the enterprise network via VPN, using a method that detects configuration changes, logs events, and allows only whitelisted traffic, ensuring secure access and maintaining a single control point for maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If portable systems are allowed to access the internet freely before connecting to enterprise VPN, then ease of operation is improved, but network security deteriorates due to risks of malware infection and data leakage

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by detecting network configuration changes before internet access is granted. The monitoring system proactively identifies when a portable system attempts to access the internet without proper VPN connection, and preemptively blocks such access. This prevents security risks before they can materialize, while still allowing users to operate their portable systems freely once properly connected.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network monitoring and blocking mechanisms are implemented for all portable systems, then network security is improved, but device complexity increases due to additional monitoring and control systems

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is implemented as a self-service solution that runs directly on each portable system. The portable system's own processor and memory resources are utilized to perform the monitoring and blocking functions, eliminating the need for complex external monitoring infrastructure. The system monitors its own network configuration changes and autonomously enforces internet access policies based on VPN connection status.

Inventive Principle:
Principle #25Self-service

3Reliability

If internet access is blocked for portable systems until VPN connection is established, then network security is improved, but productivity decreases due to restricted access to network resources

Engineering Contradiction:
Improvenetwork securityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The internet access control mechanism is dynamic rather than static. The system continuously monitors network configuration changes and automatically adjusts internet access permissions based on the current VPN connection status. When a portable system establishes a proper VPN connection, the blocking mechanism dynamically transitions from blocked to permitted state, allowing users to access both internet and enterprise network resources without manual intervention.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If user authorization details are distributed across multiple end-points for large numbers of users, then adaptability is improved, but ease of manufacture deteriorates due to complexity in managing user authorization changes

Engineering Contradiction:
ImproveadaptabilityVSAvoidease of manufacture
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The invention extracts the complex user authorization management function from individual portable systems and consolidates it into a centralized server. The server stores master user authorization details and provides authentication services to multiple portable systems. When user authorization changes occur (such as employees leaving or joining), the centralized server is updated once, and all portable systems automatically receive the updated authorization information, eliminating the need to manually update each endpoint.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8856330B2System for determining whether to block internet access of a portable system based on its current network configuration
Publication Date: 2014.10.07 FMR CORP
  • US8856330B2 patent drawing
  • US8856330B2 patent drawing
  • US8856330B2 patent drawing

AI summary

A system for monitoring a portable system external to an enterprise network is provided that includes a network monitoring system that monitors any changes to the network configuration of the portable system. If a change is detected the network monitoring system determines if the portable system is not currently connected to the enterprise network and has access to Internet so as to block access to the Internet until the portable system is properly connected to the enterprise network. An event logger receives notification from the network monitoring system and logs the status as to whether the portable system has Internet access.