Zero-Trust Network Access Control for Service-Port Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies, such as NAC, ARP spoofing, and VPN, are vulnerable to security breaches in the application layer and face challenges with policy management and man-in-the-middle attacks, especially in TCP/IP-based networks.
Innovation Solution
A system and method for controlling network access using a node with a communication circuit, processor, and memory that senses network events, identifies authorized data flows, and communicates with an external server to manage access control, blocking unauthorized data packets and ensuring secure communication through a zero-trust environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TCP/IP-based network security technologies (NAC, firewall, VPN) are used, then network access control is provided, but they are vulnerable to security breaches in the application layer and man-in-the-middle attacks
Solution Approach 1:
The patent transitions from traditional TCP/IP-based network security (operating at network and transport layers) to a zero-trust architecture that operates at the application layer and beyond. This dimensional shift enables security controls to inspect and verify actual application traffic and user identities rather than relying solely on IP addresses and network protocols, thereby preventing application layer breaches and man-in-the-middle attacks that bypass traditional perimeter security.
Solution Approach 2:
The patent introduces a zero-trust access broker as an intermediary component that mediates all network access requests. This broker verifies user identities, device states, and application contexts before granting access, and continuously monitors sessions. This intermediary layer blocks malicious traffic and prevents attacks by validating each request against security policies, rather than relying on traditional network perimeter defenses that can be bypassed.
2Reliability
If ARP spoofing is used to control unauthorized access, then unauthorized terminals are blocked, but it applies a load on the network
Solution Approach 1:
The patent extracts the access control function from network-layer protocols like ARP and implements it at the application layer through the zero-trust access broker. This separates identity verification and access authorization from the underlying network infrastructure, allowing control decisions to be made based on application context, user credentials, and device state without requiring network-wide ARP spoofing operations that consume significant bandwidth and processing resources.
Solution Approach 2:
The patent changes the parameters used for access control from network-layer identifiers (IP addresses, MAC addresses) to application-layer parameters including user identities, device states, application contexts, and security credentials. This parameter transformation enables more precise and efficient access decisions without requiring the broadcast-based ARP spoofing mechanism that generates network load.
3Ease of operation
If firewall is used to control data packet flow, then data transmission is controlled, but it may not be directly involved in the process of making a connection between two nodes
Solution Approach 1:
The patent implements preliminary action by requiring all connection requests to be pre-authenticated and authorized by the zero-trust access broker before actual data transmission begins. The broker establishes security contexts, verifies user identities, and obtains explicit authorization for each connection attempt. This preliminary security verification ensures that only authenticated and authorized connections are established, making the firewall's subsequent packet filtering more effective and reliable.
Solution Approach 2:
The patent implements continuous feedback mechanisms where the zero-trust access broker monitors ongoing connections, user activities, and device states, and dynamically adjusts access controls based on real-time security assessments. This feedback loop ensures that connection security is maintained throughout the session, not just at establishment, allowing the system to respond to changing security conditions and prevent unauthorized access attempts that might bypass static firewall rules.
Data Source
AI summary
A node according to an embodiment disclosed in the present document may comprise a communication circuit, a processor operatively connected to the communication circuit, and a memory which is operatively connected to the processor and stores a reception application and an access control application, wherein the memory stores instructions causing, when executed by the processor, the node to: detect a network reception event from a source network through the access control application; through the access control application, identify the presence or absence of a data flow which is applied from an external server and corresponds to a destination service port included in a data packet from the source network; and through the access control application, request network reception from the external server on the basis of the presence or absence of the applied data flow and whether the applied data flow includes identification information of the source network.


