Routing Device Security Modes for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the complexity of network environments increases with numerous interconnected devices, including IoT devices and mobile devices, existing network security tools struggle to efficiently manage and control network access, leading to difficulties in maintaining enhanced security and privacy, especially in unattended scenarios where malware spread and unauthorized access are concerns.

Innovation Solution

A routing device is configured with enhanced security modes that allow users to selectively disable network access for specific devices or groups of devices, enabling security settings to be adjusted based on predefined scenarios such as 'night mode' or 'away mode', using a client management and security platform that communicates with a server to implement these settings, thereby blocking network access and preventing malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network access is allowed for all devices to maintain operational flexibility, then device versatility and ease of operation are improved, but network security and vulnerability to malware spread deteriorate

Engineering Contradiction:
Improvedevice operational flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network access control by creating multiple security modes (travel mode, work mode, night mode, etc.) that can be independently selected and applied to different device groups. Each mode segments the network into different access profiles, allowing flexible control over which devices can communicate with which other devices based on the current security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts network access permissions based on the selected security mode. The routing device can real-time modification of device group assignments and access policies without requiring network reconfiguration or device reconnection, enabling operational flexibility while maintaining security through dynamic access control.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security modes are configured for each individual device, then network security is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal device groups that can be assigned to multiple security modes. A single device group configuration can serve across different security modes (e.g., a group of IoT devices can be restricted in night mode while allowed in work mode), eliminating the need to create separate configurations for each device-mode combination and significantly reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows administrators to copy existing device group configurations across multiple security modes. Once a device group is configured for one security mode, it can be replicated to other modes with minimal modification, reducing configuration effort and complexity while maintaining consistent security policies across different operational contexts.

Inventive Principle:
Principle #26Copying

3Reliability

If network access is blocked for devices not in use, then network security and malware prevention are improved, but network resource utilization and device accessibility deteriorate

Engineering Contradiction:
Improvemalware preventionVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements time-based security modes such as night mode that periodically restrict network access for devices not in use during specific time windows. During daytime or active hours, devices maintain normal access permissions, while during nighttime or unattended periods, access is automatically restricted. This periodic enforcement of security policies prevents malware spread during vulnerable periods while maintaining network productivity during active usage periods.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3732851B1Security modes for enhanced network security
Publication Date: 2024.10.02 MCAFEE LLC
  • EP3732851B1 patent drawingFigure 1
  • EP3732851B1 patent drawingFigure 2
  • EP3732851B1 patent drawingFigure 3

AI summary

Techniques related to enhanced security modes for securing a network are disclosed. The techniques include a machine readable medium, on which are stored instructions, comprising instructions that when executed cause a device to receive an indication of a security mode of a plurality of security modes, the security mode comprising a set of security settings associated with a set of network connected devices, of a plurality of network connected devices connected to a local network, and wherein the set of security settings comprises at least blocking network access of the set of network connected devices, select the set of network connected devices based on the indicated security mode, and directing an application of the set of security settings to the selected set of network connected devices.