SaaS Server Compliance Check for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network access control (NAC) systems in proprietary networks face security challenges with large numbers of users and diverse devices, requiring robust authentication and continuous monitoring that is difficult to maintain and may not be sufficiently secure.

Innovation Solution

A method and system involving a network access control server, authentication application, and device application that collect and verify compliance data on user devices, generating a compliance check result to grant or deny access based on security policies, reducing the need for continuous monitoring and enhancing security through robust authentication techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional NAC systems are used in proprietary networks with large numbers of users and diverse devices, then authentication and authorization functions are provided, but the system complexity increases and continuous monitoring becomes difficult to maintain

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the compliance check function from the traditional NAC server and implements it directly within the SaaS server. The SaaS server now performs both authentication and compliance checking internally, eliminating the need for separate NAC infrastructure and reducing system complexity while maintaining security reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the authentication application and compliance check functions into a single integrated system within the SaaS server. This consolidation combines multiple security functions into one unified process, reducing the number of components and simplifying maintenance while preserving comprehensive security control

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If traditional NAC systems implement continuous monitoring, then security is enhanced, but maintenance requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance requirements
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent performs compliance checks at the point of authentication before granting access. By conducting the compliance check upfront during the login process rather than through continuous monitoring, the system ensures security requirements are met while significantly reducing ongoing maintenance burden

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SaaS server performs self-authentication and self-compliance verification through integrated applications. The system checks its own state and makes access decisions autonomously without requiring external NAC infrastructure or continuous monitoring services, reducing maintenance requirements while maintaining security

Inventive Principle:
Principle #25Self-service

3Reliability

If additional NAC components are deployed, then access control is enforced, but the number of components increases

Engineering Contradiction:
Improveaccess controlVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines authentication and access control functions into a single integrated process within the SaaS server. By merging these previously separate functions, the system enforces access control without requiring additional NAC components, reducing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SaaS server is enhanced to perform multiple functions including authentication, compliance checking, and access control decision-making. This multi-functional approach eliminates the need for specialized NAC hardware or software components, reducing the total number of components while maintaining robust access control

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9288199B1Network access control with compliance policy check
Publication Date: 2016.03.15 OPSWAT INC
  • US9288199B1 patent drawing
  • US9288199B1 patent drawing
  • US9288199B1 patent drawing

AI summary

Embodiments of the present invention involve a method and system including a network access control server, an authentication application running on a software-as-a-service server, and a client application running on a user device. The client application collects compliance data regarding the user device and communicates the compliance data to the network access control server. The network access control server generates a compliance check result based on whether the compliance data indicates that the user device is compliant with a security policy for the software-as-a-service server. The authentication application grants access by the user device when the compliance check result is positive; and the authentication application denies access by the user device when the compliance check result is negative. In some embodiments, the compliance check result is stored in a cookie of one or more web browsers installed on the user device.