Network Quarantine via VLAN Tag Relay Destruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network quarantine systems fail to immediately isolate a terminal from the operation network even after the terminal is judged safe, as they allow connection until the quarantine agent is unlawfully uninstalled, leading to potential security breaches.

Innovation Solution

A network quarantine system comprising a quarantine agent, a relay device, and a quarantine server, where the server transmits a connection permission notification with a connection identifier and instructs the relay device to destroy information without the identifier, ensuring the terminal is not kept connected if the agent is uninstalled unlawfully, using VLAN tags to manage network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal is allowed to connect to the operation network until the quarantine agent is unlawfully uninstalled, then the network security is compromised, but the connection stability is improved

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent applies preliminary action by requiring the terminal to add a connection identifier (VLAN tag) to transmitted information before actual network communication occurs. The relay device is pre-configured to destroy information lacking this identifier, ensuring that if the quarantine agent is unlawfully uninstalled, the terminal immediately loses network access capability without requiring detection of the uninstallation event

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a connection identifier (VLAN tag) as an intermediary element between the quarantine agent and the network communication. This identifier acts as a mediator that the relay device verifies for each transmitted packet, enabling automatic destruction of unauthorized traffic without direct monitoring of the quarantine agent's operational status

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the relay device destroys all information without connection identifier, then unauthorized access is prevented, but the device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidrelay device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the relay device's information handling behavior dependent on the local presence of the connection identifier in each transmitted packet. Rather than implementing complex global security policies, the relay device simply checks for the local quality attribute (VLAN tag) in each packet and destroys or forwards accordingly, reducing overall system complexity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9319429B2Network quarantine system, network quarantine method and program therefor
Publication Date: 2016.04.19 NEC CORP
  • US9319429B2 patent drawing
  • US9319429B2 patent drawing
  • US9319429B2 patent drawing

AI summary

To isolate a terminal from a network immediately after a quarantine agent is uninstalled therefrom, a policy readout unit reads out a policy from a policy database and a policy check unit determines whether or not a terminal satisfies the policy that was read out. If it is determined that the terminal satisfies the read out policy, a quarantine server control unit instructs a bridge to destroy a packet with no VLAN tag among the packets sent from the terminal while controlling a quarantine agent to send a packet with a VLAN tag when sending the packet from the terminal.