POS Device Network Access Control via VLAN Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Point of Sale (POS) devices in retail stores face security risks due to unauthorized access to the network, leading to potential disruptions and revenue loss, as existing systems lack efficient mechanisms for controlling network access and managing device identities.
Innovation Solution
A system that utilizes a managed network switch to segment the store LAN into Virtual LANs (VLANs), where authorized POS devices are added to a specific VLAN for access to the build environment, while unauthorized devices are restricted, using a Network Access Control (NAC) system and build system that manage device identifiers and deployment of build images.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a managed network switch segments the store LAN into VLANs to control access, then network security is improved, but device complexity increases
Solution Approach 1:
The patent segments the store LAN into multiple Virtual LANs (VLANs) using a managed network switch. Authorized POS devices are placed in a first VLAN that provides access to the build environment, while unauthorized devices are restricted to a second VLAN without such access. This segmentation isolates critical build resources from potential security threats while maintaining organized network structure.
Solution Approach 2:
The managed network switch acts as an intermediary device that enforces access control policies between POS devices and the build environment. It mediates network traffic by allowing only authorized devices (those with identifiers in the access data store) to communicate with build resources, thereby implementing security without requiring complex configuration at each endpoint device.
2Reliability
If the NAC system maintains an access data store with authorized device identifiers, then access control reliability is improved, but the system complexity increases
Solution Approach 1:
The NAC system performs preliminary actions by maintaining an access data store that pre-contains identifiers of authorized POS devices before they attempt to access the build environment. This advance preparation enables the managed network switch to quickly determine authorization status without complex real-time authentication processes, simplifying the access control mechanism while maintaining reliability.
3Manufacturing precision
If the build system controls deployment of build images to POS devices, then manufacturing precision is improved, but the build process time increases
Solution Approach 1:
The build system acts as an intermediary that controls and coordinates the deployment of build images to POS devices. It manages the software update process by distributing images through the network infrastructure, ensuring accurate delivery to authorized devices while coordinating the process to minimize disruption to store operations and reduce overall build time.
Data Source
AI summary
Devices, systems, methods, and computer program products for managing network access control with a build system are disclosed. The build system controls network filtering at retail stores based on identifiers of Point of Sale devices connected to the store's LAN (Local Area Network). This filtering places only authorized devices on a virtual LAN within the LAN that is reserved for POS terminals. The network access control is managed by a process built into the build system.


