Quarantine Network System for Embedded Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional quarantine network systems are inadequate for computer-embedded apparatuses, as they struggle to set and enforce security policies, leading to vulnerabilities in network security, especially for large companies with numerous connected devices.

Innovation Solution

A quarantine network system that includes a quarantine server, isolation device, and specialized modules for inspecting and remediating computer-embedded apparatuses, which communicate with vendors' databases to determine compliance with security policies, allowing or blocking network access and updating necessary software components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional quarantine network systems are used, then general-purpose computers can be quarantined, but computer-embedded apparatuses cannot be effectively quarantined

Engineering Contradiction:
Improveadaptability to computer-embedded apparatusesVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The quarantine network system is designed to handle multiple types of devices universally. The server determines whether each connecting apparatus is a general-purpose computer or computer-embedded apparatus and applies appropriate quarantine policies accordingly, making the system adaptable to diverse device types while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Different quarantine methods are applied to different device types. General-purpose computers receive one type of quarantine treatment while computer-embedded apparatuses receive another, with each device type receiving the specific treatment quality appropriate to its characteristics and security requirements

Inventive Principle:
Principle #3Local quality

2Reliability

If security policies are enforced on computer-embedded apparatuses, then network vulnerabilities are reduced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidquarantine system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The quarantine server acts as an intermediary between network devices and the quarantine policy enforcement mechanism. It receives connection requests, determines device types, selects appropriate quarantine methods, and coordinates the quarantine process, thereby simplifying the overall system architecture while maintaining security policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system automatically determines whether each apparatus is a general-purpose computer or computer-embedded apparatus and applies the appropriate quarantine method without requiring manual configuration or administrator intervention, reducing system complexity through automated self-service

Inventive Principle:
Principle #25Self-service

3Measurement precision

If inspection criteria are set for each apparatus type, then security compliance is improved, but administrative burden increases

Engineering Contradiction:
Improvesecurity policy compliance accuracyVSAvoidadministrative effort
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The quarantine server performs preliminary determination of apparatus type before connection is fully established. By identifying whether a device is a general-purpose computer or computer-embedded apparatus in advance, the system can pre-select the appropriate quarantine method and inspection criteria, ensuring accurate security compliance checking while eliminating the need for administrators to manually configure device-specific policies

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2501100B1Quarantine network system
Publication Date: 2013.05.29 RICOH CO LTD
  • EP2501100B1 patent drawingFigure 1
  • EP2501100B1 patent drawingFigure 2
  • EP2501100B1 patent drawingFigure 3A~3B

AI summary

A quarantine network system includes a quarantine control apparatus and a quarantine client connectable with each other. The quarantine control apparatus includes a receiving unit to receive verification information of the quarantine client, an identification unit to identify a security policy that the quarantine client is required to conform to, and an inspection request unit to transmit an inspection request to the quarantine client, requesting the quarantine client to inspect conformance/non-conformance to the identified security policy. The quarantine client includes a receiver to receive the inspection request from the quarantine control apparatus, a storage unit storable inspection information to inspect conformance/non-conformance to the security policy, a reading unit to read out the inspection information from the storage unit, an inspection unit to inspect the quarantine client using the read-out inspection information, and an inspection result reporting unit to transmit an inspection result to the quarantine control apparatus.