Centralized Session Tracking for Asymmetrical Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Asymmetrical networks pose a challenge in security management as handshake messages and data packets can travel different paths, leading to erroneous session timeouts and dropped legitimate packets, as security elements in these networks do not receive all necessary handshake messages for session establishment.
Innovation Solution
An Intelligent Security System (ISS) is implemented to communicate with security elements across the network, maintaining a centralized session table that associates handshake messages from various paths, allowing it to determine whether a session is established and communicate this information to security elements, ensuring that only valid sessions are allowed to proceed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security elements are deployed in asymmetrical networks to monitor handshake messages, then network security is improved, but false session timeouts and packet drops occur because handshake messages travel different paths
Solution Approach 1:
The patent introduces a centralized session management system that acts as an intermediary between security elements and the network. This central system receives notifications of all handshake messages from multiple security elements, maintains accurate session state information, and provides authoritative session validity determinations back to security elements. This mediator resolves the information asymmetry problem by centralizing the truth about session states, eliminating false timeouts caused by path asymmetry.
Solution Approach 2:
The patent merges the session tracking functionality from distributed security elements into a single centralized session management system. Instead of each security element independently tracking sessions (which fails in asymmetrical networks), all session state information is consolidated in one central location that has complete visibility of all handshake messages across all network paths.
2Measurement precision
If centralized session tracking is implemented to resolve path asymmetry issues, then session establishment accuracy is improved, but system complexity increases
Solution Approach 1:
The centralized session management system serves as a mediator that simplifies the overall architecture despite its central role. By consolidating session tracking in one location, the system eliminates the need for complex distributed consensus mechanisms that would be required if multiple security elements tried to independently track sessions in an asymmetrical network.
3Adaptability or versatility
If security elements independently track sessions in asymmetrical networks, then device autonomy is maintained, but session state information becomes inconsistent across different security elements
Solution Approach 1:
The patent merges session tracking authority into a single centralized system that maintains the single source of truth for session states. This eliminates inconsistencies that arise when distributed security elements independently track sessions and receive different information due to path asymmetry. The centralized system ensures all security elements receive consistent session state information.
Solution Approach 2:
The centralized session management system implements feedback mechanisms where it notifies security elements of session state changes and provides authoritative determinations about session validity. This feedback loop ensures all security elements have consistent, up-to-date information about session states, resolving the inconsistency problem while maintaining system coordination.
Data Source
AI summary
Security in an asymmetrical network is addressed. At a security element, a handshake message is received on a path within the asymmetrical network. The handshake message is associated with an attempt to establish a session. A determination is made as to whether there is an entry for the handshake message in a local state table. When there is no entry in the local state table, then an entry is generated in the local state table, a notification of the handshake message is sent to a centralized computing platform that tracks handshake messages received by a plurality of security elements in the asymmetrical network, and the handshake message is allowed to pass along the path. A notification is received from the centralized computing platform that the session associated with the handshake message is allowed, based on associated handshake messages received at the centralized computing platform.


