Router Access Control with Activation-Deactivation Facility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods for networks are resource-intensive and inefficient, particularly when temporarily blocking access, as they require active checks of entered access codes despite the need to prevent external unauthorized access.

Innovation Solution

A router with a registration functionality that includes an activation/deactivation facility for temporarily blocking or releasing registration data entry, preventing the need for active checks by ensuring registration data cannot be entered when access is blocked, thus enhancing security and reducing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If active checks of entered access codes are performed to control network access, then security against unauthorized access is improved, but resource consumption and system complexity increase

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality from the router's core processing tasks by implementing a separate access control list (ACL) mechanism. This dedicated structure handles access decisions independently, removing the burden of active code checking from the main system resources while maintaining security through predefined access rules.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary action by pre-configuring access control lists with authorized user identities and access permissions before access attempts occur. The router loads these ACLs into buffer memory in advance, enabling rapid access decisions without real-time computational overhead during access control operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If active checks of entered access codes are performed continuously, then access security is maintained, but energy consumption and processing resources increase

Engineering Contradiction:
Improveaccess securityVSAvoidrouter processing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic action by updating access control lists only when necessary - specifically when access control data changes occur. The router buffer memory retains loaded ACLs until an update is required, eliminating continuous checking and reducing energy consumption to periodic updates only, while maintaining security through the persistent valid ACLs.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies self-service by designing the access control mechanism to automatically use the pre-loaded ACLs from buffer memory for all access decisions without requiring active intervention or continuous processing. The system serves itself by comparing incoming access requests against the stored ACLs, eliminating the need for continuous active checks and reducing energy consumption.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If login functionality is always available for user authentication, then ease of access is improved, but security against unwanted external access deteriorates

Engineering Contradiction:
Improveuser access convenienceVSAvoidprotection against unwanted external access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by making the login functionality conditional rather than always available. The access control lists dynamically control whether authentication is required based on the source address and destination. This allows the system to switch between requiring login (for security) and allowing direct access (for convenience) depending on the specific access scenario, optimizing both security and ease of operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3891950B1Router with login functionality and access control method suitable therefor
Publication Date: 2025.01.29 PHOENIX CONTACT GMBH & CO KG
  • EP3891950B1 patent drawingFigure 1~2
  • EP3891950B1 patent drawingFigure 3~4
  • EP3891950B1 patent drawingFigure 5

AI summary

The invention relates to an access control method and a router, which is connected between at least two communication, installation or computer networks and is equipped with login functionality and configured, for logging in a user, to grant said user access to predefined network zones and/or to network devices connected to said network zones following entry of login data recognised as permissible, characterised in that an activation/deactivation device interacting with the login functionality is provided on the router for temporarily activating and/or deactivating a login data input device required by the user for entering login data.