Authenticating Public Encryption Keys via Administrative Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies face challenges in managing security and configuration information efficiently, particularly when third-party products are used, which can introduce additional security vulnerabilities.

Innovation Solution

A method and system for managing security and permissions in a private network by using an administrative signature to authenticate public encryption keys, ensuring that only authorized computing elements can join and communicate within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party products are used to manage or secure networks, then network management capabilities are improved, but security vulnerabilities increase due to exposure of security information

Engineering Contradiction:
Improvenetwork management capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a coordination service as an intermediary between network devices and third-party management systems. This mediator handles the distribution of communication information and cryptographic materials, allowing third-party products to manage networks without direct exposure of security credentials. The coordination service acts as a trusted intermediary that protects security information while enabling enhanced network management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If encryption keys and security information are shared with third-party products, then network management functionality is improved, but security risks increase allowing unauthorized changes

Engineering Contradiction:
Improvenetwork management functionalityVSAvoidunauthorized access and changes
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The coordination service serves as a protective intermediary that enables third-party network management functionality without requiring direct access to security credentials. The service distributes communication information and cryptographic materials through controlled channels, allowing versatile network management while preventing unauthorized access by ensuring that security information is never exposed to third-party products.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary distribution of communication information and cryptographic materials through the coordination service before any third-party management operations occur. This advance setup establishes secure channels and authentication mechanisms in place, enabling functional versatility while pre-preventing unauthorized changes by ensuring that security credentials are never made available to third-party systems.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If individual networks are configured with security procedures like VLANs and encryption, then network security is improved, but configuration complexity increases making it difficult and cumbersome

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The coordination service provides a universal platform that handles multiple security functions including VLAN configuration, encryption key distribution, and authentication management through a single integrated system. This multi-functional approach maintains strong network security while reducing configuration complexity by consolidating what would otherwise require multiple separate configuration processes into one unified service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables automated self-service configuration where the coordination service automatically distributes communication information and cryptographic materials to network devices without requiring manual configuration of each security parameter. This self-service mechanism maintains robust security through proper cryptographic practices while eliminating the cumbersome manual configuration steps that would otherwise be required.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250070962A1Authentication of public encryption keys using an administrative signature
Publication Date: 2025.02.27 TAILSCALE INC
  • US20250070962A1 patent drawing
  • US20250070962A1 patent drawing
  • US20250070962A1 patent drawing

AI summary

The technology described herein manages security and permissions for a device joining a private network. In one example, a method provides, in a computing element of computing elements of a private network, receiving communication information including information for communicating with the new computing element over the private network and determining the communication information includes a public key. The method further includes, in response to determining the public key is signed with an administrative signature, adding the communication information to a communication configuration for the private network at the computing element. Also, the method includes exchanging communications between the computing element and the new computing element over the private network using the communication information from the communication configuration.