Social Graph Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for controlling access to networks, such as MAC address filtering, are cumbersome and impractical for inexperienced administrators, especially when providing guest access while maintaining security, as they require continuous updates and are resource-intensive.

Innovation Solution

Implementing a system that uses social data to authenticate users by analyzing their relationship within a social circle, allowing access based on identified electronic security policies, which can be managed through a user interface, social data module, and authentication module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods (MAC address filtering) are used to maintain network security, then security reliability is improved, but device complexity and administrative burden increase

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces social network data as an intermediary layer between the user and the network access control system. Instead of directly managing device identifiers, the system uses social relationship data (friends, connections, groups) as a mediator to determine access permissions. This reduces administrative complexity by leveraging existing social graph infrastructure while maintaining security through relationship-based policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication by allowing users to automatically authenticate based on their social network relationships without requiring manual configuration by administrators. Users' social connections are automatically analyzed to determine network access permissions, eliminating the need for administrators to manually maintain access control lists.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual tracking of device technical details is implemented to control guest access, then access control precision is improved, but loss of time and administrative burden increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidadministrative time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-establishing access control policies based on social relationships before actual network access is needed. Social network data is collected and analyzed in advance to create relationship profiles, so that when a user requests network access, authentication can be quickly determined based on pre-analyzed social connections rather than requiring real-time manual verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the social relationship graph from external social networks to use for access control decisions. Instead of manually tracking each device's technical details, the system copies and utilizes the existing social connection data structure, maintaining precise access control through relationship copying rather than device detail management.

Inventive Principle:
Principle #26Copying

3Ease of operation

If flexible guest access policies are implemented to improve ease of operation, then ease of operation is improved, but network security vulnerability increases

Engineering Contradiction:
Improveguest access managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by implementing different security policies for different social relationship types. Instead of uniform access control, the system tailors security permissions based on the specific social relationship (e.g., direct friends vs. friends of friends, different social groups), allowing flexible guest access for trusted connections while maintaining stricter security for less trusted relationships.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces dynamics by making access control policies adaptive based on social relationship changes. As social relationships evolve (new friends, broken connections, group memberships changing), access permissions automatically adjust accordingly. This dynamic approach maintains ease of operation while managing security vulnerabilities through continuous relationship-based policy updates.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9565194B2Utilizing a social graph for network access and admission control
Publication Date: 2017.02.07 MCAFEE LLC
  • US9565194B2 patent drawing
  • US9565194B2 patent drawing
  • US9565194B2 patent drawing

AI summary

Technologies for providing access control for a network are disclosed. The method may include receiving a request from a user to access a network, receiving a plurality of data associated with the user, the plurality of data comprising a plurality of social data associated with the user's relationship to a social circle, identifying an electronic security policy based at least on the plurality of social data, and authenticating the user to the network if the electronic security policy permits authentication based at least on the plurality of social data.