Network Switch Dynamic Access Control Based on Device Health

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network switch technologies cannot dynamically and automatically apply access control configurations based on the health state of connecting devices, relying on static manual configurations for VLAN assignments and ACLs.

Innovation Solution

A method where the network switch receives and evaluates the health status of connected devices, using network access rules to dynamically apply VLAN or ACL configurations, potentially changing device access levels based on computed health states, either from local agents or cloud-based threat management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static manual configuration is used for VLAN assignments and ACLs, then device complexity is reduced and ease of operation is improved, but adaptability to device health states deteriorates and network security responsiveness worsens

Engineering Contradiction:
Improveadaptability to device health statesVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network switch automatically monitors device health status through integrated agents and applies appropriate VLAN/ACL configurations without requiring manual administrator intervention. The system self-adjusts network access control based on real-time device health assessments, eliminating the need for complex manual reconfiguration when device states change.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transitions from static manual configurations to dynamic automatic configurations that respond in real-time to changing device health states. The network switch continuously monitors device conditions and dynamically adjusts VLAN assignments and ACL rules based on current health status, enabling adaptive network security management.

Inventive Principle:
Principle #15Dynamics

2Reliability

If dynamic automatic application of access control configurations is implemented, then network security responsiveness is improved and adaptability to device health states is enhanced, but device complexity increases and ease of operation deteriorates

Engineering Contradiction:
Improvenetwork security responsivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides network access control into separate functional components: device health monitoring agents, health status evaluation modules, and VLAN/ACL configuration applications. This segmentation allows each component to operate independently and simplifies the overall system architecture while enabling dynamic automatic configuration based on device health states.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network switch implements a feedback loop where device health status information continuously flows from monitoring agents back to the switch, which then automatically adjusts configurations based on this feedback. This closed-loop system enhances security responsiveness while maintaining manageable complexity through standardized feedback mechanisms.

Inventive Principle:
Principle #23Feedback

3Productivity

If manual configuration of VLANs and ACLs is used, then ease of operation is improved and device complexity is reduced, but productivity of network security management deteriorates and loss of time increases

Engineering Contradiction:
Improvenetwork security management productivityVSAvoidconfiguration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system pre-configures multiple VLANs and ACL rules in advance, along with predefined device health assessment criteria. When devices connect or their health status changes, the network switch immediately applies the appropriate pre-configured settings without requiring real-time manual configuration, significantly reducing response time and improving security management productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network switch automatically performs configuration tasks based on device health status without requiring administrator time or intervention. The system self-manages VLAN assignments and ACL applications, eliminating the time loss associated with manual configuration processes and enabling rapid response to changing network conditions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11962621B2Applying network access control configurations with a network switch based on device health
Publication Date: 2024.04.16 SOPHOS LTD
  • US11962621B2 patent drawing
  • US11962621B2 patent drawing
  • US11962621B2 patent drawing

AI summary

A method includes receiving, by a computer system, information related to device health of an electronic device, determining, by the computer system, a health status of the electronic device based at least in part on the received information related to the device health of the electronic device, requesting, by a switch having a port connected to the electronic device, the health status of the electronic device from the computer system, receiving, by the computer system, the request for the health status of the electronic device from the switch, transmitting, by the computer system, the health status of the electronic device to the switch, evaluating, by the switch, the transmitted health status of the electronic device using network access rules associated corresponding to health statuses, and applying, by the switch, a network access control configuration to the port of the switch based on the evaluating the transmitted health status.