Switch Port Leasing for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems are unable to preemptively identify and block malicious network devices, allowing unauthorized access and data leakage, as they typically detect malicious activity after it has occurred, limiting their ability to provide effective information security and data access control.

Innovation Solution

The system identifies and blocks potentially malicious network devices by comparing device and location information from device logs with actual switch data, activating temporary port leases based on device authentication status, and enabling port authentication to monitor and control access, thereby preventing malicious activities before they occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional detection systems are used to identify malicious network devices, then detection capability is provided, but detection occurs only after malicious activity has already taken place

Engineering Contradiction:
Improvedetection timingVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by comparing device information against logs and assigning risk scores before malicious activity occurs. This allows the system to identify and block potentially malicious devices proactively, preventing data exfiltration and malicious activities before they can take place, rather than detecting them only after damage has been done.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by blocking network access for devices with high risk scores before they can perform malicious activities. This preemptive blocking prevents malicious devices from extracting data or performing harmful actions, directly counteracting potential threats before they materialize.

Inventive Principle:
Principle #9Preliminary anti-action

2Ease of operation

If network access is freely provided to all devices, then network usability is improved, but security vulnerability increases due to unauthorized access

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by providing differentiated network access based on individual device risk assessments. Rather than uniform access control, each device receives appropriate access rights according to its calculated risk score and authentication results, allowing legitimate devices full access while restricting potentially malicious ones.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the access parameter dynamically based on device risk scores. Devices undergo authentication and information comparison, and their network access rights are adjusted according to the results - high-risk devices are blocked while low-risk devices receive normal access, creating adaptive security control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive device monitoring is implemented to improve security detection, then security capability is enhanced, but system complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by having devices automatically undergo authentication and information comparison processes without manual intervention. The automated workflow collects device information, compares it against logs, calculates risk scores, and makes access decisions autonomously, reducing the need for complex manual security management while maintaining high security capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback mechanisms where device information is continuously collected, compared against historical logs, and used to update risk assessments. This closed-loop feedback process enables the system to learn from past devices and improve its detection accuracy over time without requiring proportional increases in system complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10320804B2Switch port leasing for access control and information security
Publication Date: 2019.06.11 BANK OF AMERICA CORP
  • US10320804B2 patent drawing
  • US10320804B2 patent drawing
  • US10320804B2 patent drawing

AI summary

A system that includes a switch, a network authentication server (NAS), and a threat management server. The threat management server receives a port lease request for the endpoint device identifying a port and the endpoint device. The threat management server determines whether the endpoint device has previously failed authentication with the NAS. In response to determining the endpoint device has not previously failed authentication, the threat management server selects a first port lease duration when a device identifier for the endpoint device is present in the port lease. The threat management server selected a second port lease duration that is a shorter amount of time than the first port lease duration when the device identifier for the endpoint device is not present in the port lease request. The threat management server activates a port lease for the selected port lease duration.