Router-Host Logging for Granular Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network logging and access control systems lack comprehensive mechanisms to manage and enforce access rules across multiple devices at a user location, particularly when accessing different network service providers, and fail to provide detailed logging and reporting capabilities for content access.

Innovation Solution

A network interface device at a user location receives and logs requests from multiple machines, applies network access control rules to grant or deny access to network locations, and provides logging and reporting functionalities, enabling granular control and monitoring of internet access across all connected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a network interface device logs requests from multiple machines separately into individual logs, then the logging precision and ability to monitor specific machine usage is improved, but the device complexity and storage requirements increase

Engineering Contradiction:
Improvelogging precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the logging system into separate machine-specific log files, where each log file stores requests from a specific machine identified by its identifier. This segmentation allows precise tracking of individual machine usage while maintaining organizational simplicity through clear separation of data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of organization by creating logs specific to each machine rather than using a single consolidated log. This dimensional change from a unified log structure to a multi-dimensional machine-specific log structure enables precise per-machine monitoring without requiring complex cross-referencing systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If the network interface device applies network access control rules to limit service from different network service providers, then the ability to control and restrict access is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improveaccess control capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control mechanism where a single network interface device handles multiple network service providers and applies the same access control rules across all providers. This multi-functional approach allows the device to control access from various ISPs using a unified rule set, reducing the need for provider-specific control systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network interface device acts as an intermediary between machines and multiple network service providers, intercepting requests and applying access control rules before forwarding to the appropriate provider. This intermediary position enables centralized control without requiring direct integration with each service provider's system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If the network interface device provides detailed logging and reporting functionalities for multiple machines, then the monitoring capability is improved, but the use of energy and processing resources increases

Engineering Contradiction:
Improveinformation retentionVSAvoidenergy consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent extracts and stores detailed request information into persistent log files on storage media, separating the information retention function from active processing. This extraction allows the device to maintain comprehensive logs without continuously consuming processing resources, as the data is stored passively and can be analyzed later without active intervention.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10673985B2Router-host logging
Publication Date: 2020.06.02 VERIZON PATENT & LICENSING INC
  • US10673985B2 patent drawing
  • US10673985B2 patent drawing
  • US10673985B2 patent drawing

AI summary

According to a general aspect, a method includes receiving, at a network interface device at a user location, a request from a first machine located at the user location, the request including a first-machine identifier and a request to access through the network interface device a first location on a network. The method also includes logging, at the network interface device, the request from the first machine into a first-machine log for requests from the first machine, the logging into the first-machine log being based on the first-machine identifier. The method also includes receiving at the network interface device a request from a second machine located at the user location, the request from the second machine including a second-machine identifier and a request to access through the network interface device a second location on the network, and the network interface device, the first machine, and the second machine being located at a user location. The method further includes logging, at the network interface device, the request from the second machine into a second-machine log for all requests from the second machine, the logging into the second-machine log being based on the second-machine identifier.