Application Service Level Protocol for Network Traffic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current networks, such as the Internet, configured as 'best effort' networks, face challenges in providing reliable minimum application levels of service due to bandwidth hogging by certain applications, which can starve other applications of resources, and port-level configurations are limited in discriminating between applications and vulnerable to spoofing.
Innovation Solution
Implementing a system that maintains a list of registered applications, authenticates users, and generates application service level protocol (ASLP) data to manage network resources and provide reliable application levels of service, preventing unauthenticated applications from spoofing the network by using ASLP information to handle and route network traffic accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port-level configuration is used to prioritize certain packets, then minimum level of service is maintained for those packets, but applications can easily spoof the network to exploit the configuration
Solution Approach 1:
The patent changes the discrimination parameter from port-level to application-level by implementing deep packet inspection. The system examines packet payloads, protocols, and traffic patterns to identify applications, thereby changing the parameter of identification from superficial (port numbers) to substantive (application behavior and characteristics). This resolves the spoofing issue while maintaining service differentiation.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the network and applications. A trusted third party (application provider) signs certificates that verify application identities. This intermediary layer prevents spoofing by providing cryptographic verification of application authenticity, allowing the network to trust only authenticated applications while maintaining service level differentiation.
2Adaptability or versatility
If best effort protocols are used to maintain network neutrality, then compatibility with any application is achieved, but bandwidth resources are hogged by certain applications starving other applications
Solution Approach 1:
The patent segments network traffic management into multiple levels: application identification, authentication verification, and service level enforcement. By dividing the traffic handling process into distinct stages with specific functions, the system can maintain overall network neutrality while applying differentiated service levels to authenticated applications, preventing bandwidth hogging without compromising adaptability.
Solution Approach 2:
The patent implements dynamic service level adjustment based on authenticated application identities. Rather than static port-based rules, the system dynamically determines service levels by verifying application certificates and matching them against authorized service level agreements. This dynamic approach maintains network neutrality for unauthenticated traffic while providing reliable bandwidth allocation for authenticated applications.
3Reliability
If application-level discrimination is implemented to prevent spoofing, then reliable service levels can be provided, but device complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where applications automatically obtain authentication certificates from trusted providers and present them to the network. The network infrastructure automatically verifies certificates and enforces service levels without manual configuration for each application. This self-service approach reduces device complexity by automating the authentication and service level enforcement processes.
Solution Approach 2:
The patent performs preliminary authentication and certificate verification before service level enforcement. Applications are authenticated in advance by trusted providers, and their service levels are predetermined through automated policy matching. This preliminary action simplifies network device complexity by shifting the complex identification and authorization tasks to external authentication systems rather than requiring complex local configuration.
Data Source
AI summary
Methods, systems, devices, and software are disclosed for providing application levels of service over a network. Embodiments of the invention maintain a list of registered applications (or application providers) that have registered with a network resources provider. Customers of the network resources provider may authenticate some or all of the registered applications, indicating a desire to allow traffic relating to those applications over their access networks. Customers may further set application levels of service with respect to those authenticated applications. Certain embodiments may use the registrations, authentications, service level settings, and/or other related information to generate application service level protocol data. This ASLP data may then be used to make data handling determinations for managing the flow of network traffic according to agreed service levels at the application level.


