SaaS Server Compliance Check for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network access control (NAC) systems in proprietary networks face security challenges with large numbers of users and diverse devices, requiring robust authentication and continuous monitoring that is difficult to maintain and may not be sufficiently secure.
Innovation Solution
A method and system involving a network access control server, authentication application, and device application that collect and verify compliance data on user devices, generating a compliance check result to grant or deny access based on security policies, reducing the need for continuous monitoring and enhancing security through robust authentication techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional NAC systems are used in proprietary networks with large numbers of users and diverse devices, then authentication and authorization functions are provided, but the system complexity increases and continuous monitoring becomes difficult to maintain
Solution Approach 1:
The patent extracts the compliance check function from the traditional NAC server and implements it directly within the SaaS server. The SaaS server now performs both authentication and compliance checking internally, eliminating the need for separate NAC infrastructure and reducing system complexity while maintaining security reliability
Solution Approach 2:
The patent merges the authentication application and compliance check functions into a single integrated system within the SaaS server. This consolidation combines multiple security functions into one unified process, reducing the number of components and simplifying maintenance while preserving comprehensive security control
2Reliability
If traditional NAC systems implement continuous monitoring, then security is enhanced, but maintenance requirements increase
Solution Approach 1:
The patent performs compliance checks at the point of authentication before granting access. By conducting the compliance check upfront during the login process rather than through continuous monitoring, the system ensures security requirements are met while significantly reducing ongoing maintenance burden
Solution Approach 2:
The SaaS server performs self-authentication and self-compliance verification through integrated applications. The system checks its own state and makes access decisions autonomously without requiring external NAC infrastructure or continuous monitoring services, reducing maintenance requirements while maintaining security
3Reliability
If additional NAC components are deployed, then access control is enforced, but the number of components increases
Solution Approach 1:
The patent combines authentication and access control functions into a single integrated process within the SaaS server. By merging these previously separate functions, the system enforces access control without requiring additional NAC components, reducing overall system complexity
Solution Approach 2:
The SaaS server is enhanced to perform multiple functions including authentication, compliance checking, and access control decision-making. This multi-functional approach eliminates the need for specialized NAC hardware or software components, reducing the total number of components while maintaining robust access control
Data Source
AI summary
Embodiments of the present invention involve a method and system including a network access control server, an authentication application running on a software-as-a-service server, and a client application running on a user device. The client application collects compliance data regarding the user device and communicates the compliance data to the network access control server. The network access control server generates a compliance check result based on whether the compliance data indicates that the user device is compliant with a security policy for the software-as-a-service server. The authentication application grants access by the user device when the compliance check result is positive; and the authentication application denies access by the user device when the compliance check result is negative. In some embodiments, the compliance check result is stored in a cookie of one or more web browsers installed on the user device.


