Router-Based LAN Access Control for Unauthorized Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Local area networks (LANs) face bandwidth reduction and unauthorized access issues due to unmanaged device connections, leading to inconvenience for administrators who need to reset passwords to prevent unauthorized access.

Innovation Solution

A system and method for managing computing device access to LANs, where a router determines the authorization status of client devices and sends requests to an administrator for approval or blocking, using a network administration application to manually or automatically allow or block access based on prior authorization and administrative keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password protection is used to manage device connections, then network security is improved, but device complexity and ease of operation deteriorate due to frequent password resets

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically detects unauthorized devices and generates notifications for administrator approval without requiring manual password changes. The router autonomously manages the authorization process by monitoring connection requests and facilitating administrator decision-making, eliminating the need for users to manually reset passwords when security issues arise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback loop where the router continuously monitors connection attempts, identifies unauthorized devices, and notifies the administrator for approval. This closed-loop system provides real-time security management and allows dynamic adjustment of access permissions based on current network conditions and administrator decisions.

Inventive Principle:
Principle #23Feedback

2Reliability

If password protection is used to prevent unauthorized access, then network security is improved, but ease of operation worsens as users must change login information frequently

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidlogin management convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The router autonomously monitors for unauthorized devices and initiates the authorization process by sending notifications to administrators. This self-service approach eliminates the need for users to manually intervene or change passwords, as the system automatically manages security enforcement and permission updates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authorization checks before allowing device connections. By proactively identifying and managing unauthorized devices before they can cause harm, the system prevents security issues rather than reacting to them, thereby maintaining both security and operational smoothness.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If connection password is reset to prevent guest access, then unauthorized access prevention is improved, but productivity deteriorates due to time required for password changes

Engineering Contradiction:
Improveguest access controlVSAvoidaccess management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system establishes a real-time feedback mechanism where the router monitors connection attempts, identifies guest devices, and immediately notifies the administrator for approval. This continuous monitoring and rapid response system eliminates the need for periodic password resets, maintaining security while maximizing operational efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The router autonomously performs the tedious work of monitoring connections, identifying unauthorized devices, and managing the authorization workflow. This automation of security management tasks frees administrators from time-consuming manual password changes while maintaining robust guest access control.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If multiple devices are connected to LAN, then adaptability is improved, but bandwidth availability deteriorates leading to slower data transmission

Engineering Contradiction:
Improvedevice connection flexibilityVSAvoiddata transmission speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The system automatically monitors network bandwidth usage and identifies devices consuming excessive resources. By autonomously detecting and managing bandwidth-hogging devices through administrator approval workflows, the system maintains network performance while allowing flexible device connections.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10567387B1Systems and methods for managing computing device access to local area computer networks
Publication Date: 2020.02.18 GEN DIGITAL INC
  • US10567387B1 patent drawing
  • US10567387B1 patent drawing
  • US10567387B1 patent drawing

AI summary

The disclosed computer-implemented method for managing computing device access to local area computer networks may include (i) receiving, at a router computing device, a request to connect a client computing device to a local area computer network, (ii) determining whether the client computing device has prior authorization to connect to the local area computer network, (iii) sending, when the client computing device is determined to not have prior authorization, a request to an administrator computing device for authorization to connect the client computing device to the local area computer network, (iv) receiving, from the administrator computing device, an instruction to allow the client computing device to connect or to block the client computing device from connecting, and (v) performing a security action to block or allow the client computing device's request based on the instruction. Various other methods, systems, and computer-readable media are also disclosed.