User Device Network Onboarding via Security Profile Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring secure and convenient network access for organizations by verifying the security of user devices, both those brought into the network and those issued by the organization, while avoiding inconvenience to users.

Innovation Solution

A user-based network onboarding system that assigns security profiles to devices, configuring them for network access based on network configuration information, and implementing security techniques such as password protection and biometric authentication to ensure authorized access to trusted and untrusted resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security verification processes are implemented to ensure network access security, then network security is improved, but user convenience deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs security verification in advance during the network onboarding process. Devices are evaluated against security criteria before being granted network access, and security profiles are pre-configured. This preliminary security check ensures that only compliant devices gain access, maintaining high security standards while avoiding repeated verification during normal use, thus preserving user convenience.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual security verification processes are used to ensure device security, then security control is improved, but processing time increases

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables devices to perform self-verification against predefined security criteria. During onboarding, devices automatically provide their security attributes and configurations, which are then evaluated by the network system. This self-service approach eliminates the need for manual security verification by administrators, significantly reducing processing time while maintaining rigorous security control through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms security verification from a manual, time-consuming process into an automated parameter-based evaluation. By defining security requirements as configurable parameters and criteria, the system can automatically assess devices against these parameters using machine-readable formats. This parameterization enables rapid, consistent security evaluation without manual intervention, resolving the contradiction between security control and processing time.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security profiles are assigned to all devices, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security profiles into hierarchical levels (e.g., first-level and second-level security profiles) and assigns them based on device types, user roles, and network requirements. Rather than implementing a single monolithic security framework, the segmented approach allows granular control over security policies for different device categories. This segmentation maintains comprehensive security coverage while reducing overall system complexity by breaking down the security management task into manageable, modular components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates universal security profiles that can be applied across multiple devices and contexts. A single security profile template can serve multiple device types with similar requirements, and the same profile can be reused across different network environments. This universality reduces the number of unique security configurations needed, thereby decreasing system complexity while ensuring consistent security coverage across the entire device fleet.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10320847B2User-based network onboarding
Publication Date: 2019.06.11 EXTREME NETWORKS INC
  • US10320847B2 patent drawing
  • US10320847B2 patent drawing
  • US10320847B2 patent drawing

AI summary

A request related to an access to a network by a first user device may be received. The user device may be included in a plurality of user devices associated with a first first-level security profile assigned to the user. An application extension to an application executing on the first user device may be accessed in response to the request related to the access. A network connectivity file may be provided to the application extension. The network connectivity file may include network configuration information for the first user device. The network configuration information may be associated with a first second-level security profile assigned to the first user device. Instructions to configure the first user device to access the network based at least in part on the network configuration information in the network connectivity file may be provided.