POS Device Network Access Control via VLAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Point of Sale (POS) devices in retail stores face security risks due to unauthorized access to the network, leading to potential disruptions and revenue loss, as existing systems lack efficient mechanisms for controlling network access and managing device identities.

Innovation Solution

A system that utilizes a managed network switch to segment the store LAN into Virtual LANs (VLANs), where authorized POS devices are added to a specific VLAN for access to the build environment, while unauthorized devices are restricted, using a Network Access Control (NAC) system and build system that manage device identifiers and deployment of build images.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a managed network switch segments the store LAN into VLANs to control access, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the store LAN into multiple Virtual LANs (VLANs) using a managed network switch. Authorized POS devices are placed in a first VLAN that provides access to the build environment, while unauthorized devices are restricted to a second VLAN without such access. This segmentation isolates critical build resources from potential security threats while maintaining organized network structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The managed network switch acts as an intermediary device that enforces access control policies between POS devices and the build environment. It mediates network traffic by allowing only authorized devices (those with identifiers in the access data store) to communicate with build resources, thereby implementing security without requiring complex configuration at each endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the NAC system maintains an access data store with authorized device identifiers, then access control reliability is improved, but the system complexity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NAC system performs preliminary actions by maintaining an access data store that pre-contains identifiers of authorized POS devices before they attempt to access the build environment. This advance preparation enables the managed network switch to quickly determine authorization status without complex real-time authentication processes, simplifying the access control mechanism while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If the build system controls deployment of build images to POS devices, then manufacturing precision is improved, but the build process time increases

Engineering Contradiction:
Improvesoftware deployment accuracyVSAvoidbuild process time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The build system acts as an intermediary that controls and coordinates the deployment of build images to POS devices. It manages the software update process by distributing images through the network infrastructure, ensuring accurate delivery to authorized devices while coordinating the process to minimize disruption to store operations and reduce overall build time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10922414B2Point of sale device build security
Publication Date: 2021.02.16 TARGET BRANDS INC
  • US10922414B2 patent drawing
  • US10922414B2 patent drawing
  • US10922414B2 patent drawing

AI summary

Devices, systems, methods, and computer program products for managing network access control with a build system are disclosed. The build system controls network filtering at retail stores based on identifiers of Point of Sale devices connected to the store's LAN (Local Area Network). This filtering places only authorized devices on a virtual LAN within the LAN that is reserved for POS terminals. The network access control is managed by a process built into the build system.