Hierarchical Trust Posture Reporting for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in preventing internal breaches and rogue access, as they rely on device authentication and posture validation after access is initiated, leaving networks vulnerable to unauthorized access and malware transmission from external connections.

Innovation Solution

A network access scheme involving an access requester, policy enforcement point, and policy decision point, utilizing a manageability engine to gather and validate posture information through secure communication channels, establishing hierarchical trust layers and remediation actions to ensure secure access and containment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security measures (IEEE 802.1X, EAP) are used for device authentication before access, then network access control is improved, but the system cannot prevent internal breaches and rogue access from within the network

Engineering Contradiction:
Improvenetwork access controlVSAvoidinternal breaches and rogue access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by evaluating device posture and security status continuously before and during network access, rather than only at initial authentication. The system performs posture assessments, vulnerability scans, and security validation prior to granting access and maintains these evaluations throughout the access period to prevent internal breaches and rogue access from within the network.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If posture validation is performed after access is initiated, then network access speed is improved, but security coverage is insufficient to prevent malware transmission and unauthorized access

Engineering Contradiction:
Improvenetwork access speedVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs posture validation and security assessments before network access is fully initiated, establishing security clearances in advance. This allows the network to grant access while maintaining continuous monitoring and validation, ensuring both fast access and comprehensive security coverage against malware transmission and unauthorized access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous posture validation and security monitoring throughout the network access period, rather than a single pre-access check. This continuous action ensures that security coverage remains effective while allowing rapid access, as the system continuously validates device posture, detects vulnerabilities, and maintains security clearances without blocking legitimate access.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If strict access control policies are enforced for network connection, then network security is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components including posture assessment servers, validation servers, and security gateways that mediate between devices and the network. These intermediaries handle complex security evaluations, posture validations, and access control decisions, reducing the complexity burden on individual devices while maintaining strict network security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs multi-functional security infrastructure that combines authentication, authorization, posture validation, vulnerability assessment, and access control in unified platforms. This multi-functionality reduces implementation complexity by consolidating security functions rather than requiring separate systems for each security measure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7703126B2Hierarchical trust based posture reporting and policy enforcement
Publication Date: 2010.04.20 INTEL CORP
  • US7703126B2 patent drawing
  • US7703126B2 patent drawing
  • US7703126B2 patent drawing

AI summary

A method that includes initiating a network access request from an access requester on a platform that couples to a network, the network access request made to a policy decision point for the network. The method also includes establishing a secure communication channel over a communication link between the policy decision point and a policy enforcement point on the platform. Another secure communication channel is established over another communication link. The other communication link is between at least the policy enforcement point and a manageability engine resident on the platform. The manageability engine forwards posture information associated with the access requester via the other secure communication channel. The posture information is then forwarded to the policy decision point via the secure communication channel between the policy enforcement point and the policy decision point. The policy decision point indicates what access the access requester can obtain to the network based on a comparison of the posture information to one or more network administrative policies.