Hierarchical Trust Posture Reporting for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures are inadequate in preventing internal breaches and rogue access, as they rely on device authentication and posture validation after access is initiated, leaving networks vulnerable to unauthorized access and malware transmission from external connections.
Innovation Solution
A network access scheme involving an access requester, policy enforcement point, and policy decision point, utilizing a manageability engine to gather and validate posture information through secure communication channels, establishing hierarchical trust layers and remediation actions to ensure secure access and containment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security measures (IEEE 802.1X, EAP) are used for device authentication before access, then network access control is improved, but the system cannot prevent internal breaches and rogue access from within the network
Solution Approach 1:
The patent applies preliminary action by evaluating device posture and security status continuously before and during network access, rather than only at initial authentication. The system performs posture assessments, vulnerability scans, and security validation prior to granting access and maintains these evaluations throughout the access period to prevent internal breaches and rogue access from within the network.
2Productivity
If posture validation is performed after access is initiated, then network access speed is improved, but security coverage is insufficient to prevent malware transmission and unauthorized access
Solution Approach 1:
The system performs posture validation and security assessments before network access is fully initiated, establishing security clearances in advance. This allows the network to grant access while maintaining continuous monitoring and validation, ensuring both fast access and comprehensive security coverage against malware transmission and unauthorized access.
Solution Approach 2:
The patent implements continuous posture validation and security monitoring throughout the network access period, rather than a single pre-access check. This continuous action ensures that security coverage remains effective while allowing rapid access, as the system continuously validates device posture, detects vulnerabilities, and maintains security clearances without blocking legitimate access.
3Reliability
If strict access control policies are enforced for network connection, then network security is improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces intermediary components including posture assessment servers, validation servers, and security gateways that mediate between devices and the network. These intermediaries handle complex security evaluations, posture validations, and access control decisions, reducing the complexity burden on individual devices while maintaining strict network security policies.
Solution Approach 2:
The system employs multi-functional security infrastructure that combines authentication, authorization, posture validation, vulnerability assessment, and access control in unified platforms. This multi-functionality reduces implementation complexity by consolidating security functions rather than requiring separate systems for each security measure.
Data Source
AI summary
A method that includes initiating a network access request from an access requester on a platform that couples to a network, the network access request made to a policy decision point for the network. The method also includes establishing a secure communication channel over a communication link between the policy decision point and a policy enforcement point on the platform. Another secure communication channel is established over another communication link. The other communication link is between at least the policy enforcement point and a manageability engine resident on the platform. The manageability engine forwards posture information associated with the access requester via the other secure communication channel. The posture information is then forwarded to the policy decision point via the secure communication channel between the policy enforcement point and the policy decision point. The policy decision point indicates what access the access requester can obtain to the network based on a comparison of the posture information to one or more network administrative policies.


