Quarantine Network System for Embedded Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional quarantine network systems are inadequate for computer-embedded apparatuses, as they struggle to set and enforce security policies, leading to vulnerabilities in network security, especially for large companies with numerous connected devices.
Innovation Solution
A quarantine network system that includes a quarantine server, isolation device, and specialized modules for inspecting and remediating computer-embedded apparatuses, which communicate with vendors' databases to determine compliance with security policies, allowing or blocking network access and updating necessary software components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional quarantine network systems are used, then general-purpose computers can be quarantined, but computer-embedded apparatuses cannot be effectively quarantined
Solution Approach 1:
The quarantine network system is designed to handle multiple types of devices universally. The server determines whether each connecting apparatus is a general-purpose computer or computer-embedded apparatus and applies appropriate quarantine policies accordingly, making the system adaptable to diverse device types while maintaining security
Solution Approach 2:
Different quarantine methods are applied to different device types. General-purpose computers receive one type of quarantine treatment while computer-embedded apparatuses receive another, with each device type receiving the specific treatment quality appropriate to its characteristics and security requirements
2Reliability
If security policies are enforced on computer-embedded apparatuses, then network vulnerabilities are reduced, but system complexity increases
Solution Approach 1:
The quarantine server acts as an intermediary between network devices and the quarantine policy enforcement mechanism. It receives connection requests, determines device types, selects appropriate quarantine methods, and coordinates the quarantine process, thereby simplifying the overall system architecture while maintaining security policy enforcement
Solution Approach 2:
The system automatically determines whether each apparatus is a general-purpose computer or computer-embedded apparatus and applies the appropriate quarantine method without requiring manual configuration or administrator intervention, reducing system complexity through automated self-service
3Measurement precision
If inspection criteria are set for each apparatus type, then security compliance is improved, but administrative burden increases
Solution Approach 1:
The quarantine server performs preliminary determination of apparatus type before connection is fully established. By identifying whether a device is a general-purpose computer or computer-embedded apparatus in advance, the system can pre-select the appropriate quarantine method and inspection criteria, ensuring accurate security compliance checking while eliminating the need for administrators to manually configure device-specific policies
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A quarantine network system includes a quarantine control apparatus and a quarantine client connectable with each other. The quarantine control apparatus includes a receiving unit to receive verification information of the quarantine client, an identification unit to identify a security policy that the quarantine client is required to conform to, and an inspection request unit to transmit an inspection request to the quarantine client, requesting the quarantine client to inspect conformance/non-conformance to the identified security policy. The quarantine client includes a receiver to receive the inspection request from the quarantine control apparatus, a storage unit storable inspection information to inspect conformance/non-conformance to the security policy, a reading unit to read out the inspection information from the storage unit, an inspection unit to inspect the quarantine client using the read-out inspection information, and an inspection result reporting unit to transmit an inspection result to the quarantine control apparatus.