Quarantined Server for Secure Network Node Admission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securely adding a node to a network are costly and inefficient, as they often require specialized routers and switches, leading to increased computing downtime and vulnerability to security threats when a new node may be infected with viruses or not properly secured.

Innovation Solution

Implementing a system where a quarantined server directs all network address requests, using a validation module to assess candidate nodes for security criteria, issuing a quarantined network address for initial access, and optionally remediating non-compliant nodes, thereby preventing unauthorized access to the main network without the need for specialized hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary routers and switches are installed to securely add a node, then network security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a quarantined server as an intermediary component between new nodes and the main network. This server captures network address requests, validates security criteria, and selectively relays requests to the network address server. This intermediary approach achieves secure node addition without requiring specialized routers and switches, thereby maintaining network security while avoiding increased device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary routers and switches are installed to securely add a node, then network security is improved, but monetary cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs a software-based validation module running on a standard server rather than expensive proprietary hardware. The quarantined server uses conventional routers and switches instead of specialized network infrastructure. This approach replaces costly, specialized hardware with affordable, general-purpose computing resources, significantly reducing implementation costs while maintaining security through software-based validation and control mechanisms.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If conventional routers and switches are used without validation, then device complexity is reduced, but network security deteriorates

Engineering Contradiction:
Improvenetwork infrastructure complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security validation before allowing new nodes to access the network address server. The validation module checks security criteria in advance, and only authorized nodes receive network addresses. This preliminary action prevents potentially malicious nodes from compromising the network, maintaining security while using conventional, simple network infrastructure.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If security validation is implemented for new nodes, then network security is improved, but computing downtime increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnode addition downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The quarantined server operates continuously, capturing and validating network address requests from new nodes in real-time. The validation process occurs in the background without requiring network shutdown or disruption. Once validation is complete, the node is seamlessly integrated into the network. This continuous operation maintains network security while minimizing downtime during node addition.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8584194B1Network access control using a quarantined server
Publication Date: 2013.11.12 IVANTI INC
  • US8584194B1 patent drawing
  • US8584194B1 patent drawing
  • US8584194B1 patent drawing

AI summary

Network address requests from candidate nodes are directed to a quarantined server rather than a network address server. The candidate node is admitted to a virtual network, enabling the candidate node to access only limited resources of the network and minimizing security risks to the network. The quarantined server determines whether the candidate node complies with a set of security criteria. If the candidate node conforms to the set of criteria, when a second request for a network address is sent by the candidate node, the second request is received by the quarantined server and relayed to the network address server. Thereafter, the network address server will issue a network address to the candidate node, enabling the candidate node to access at least a portion of the full resources of the network. If the candidate node does not comply with the security criteria and cannot be remediated, the network address server will not issue a network address to the candidate node.