Centralized Session Tracking for Asymmetrical Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Asymmetrical networks pose a challenge in security management as handshake messages and data packets can travel different paths, leading to erroneous session timeouts and dropped legitimate packets, as security elements in these networks do not receive all necessary handshake messages for session establishment.

Innovation Solution

An Intelligent Security System (ISS) is implemented to communicate with security elements across the network, maintaining a centralized session table that associates handshake messages from various paths, allowing it to determine whether a session is established and communicate this information to security elements, ensuring that only valid sessions are allowed to proceed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security elements are deployed in asymmetrical networks to monitor handshake messages, then network security is improved, but false session timeouts and packet drops occur because handshake messages travel different paths

Engineering Contradiction:
Improvenetwork securityVSAvoidhandshake message tracking accuracy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a centralized session management system that acts as an intermediary between security elements and the network. This central system receives notifications of all handshake messages from multiple security elements, maintains accurate session state information, and provides authoritative session validity determinations back to security elements. This mediator resolves the information asymmetry problem by centralizing the truth about session states, eliminating false timeouts caused by path asymmetry.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the session tracking functionality from distributed security elements into a single centralized session management system. Instead of each security element independently tracking sessions (which fails in asymmetrical networks), all session state information is consolidated in one central location that has complete visibility of all handshake messages across all network paths.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If centralized session tracking is implemented to resolve path asymmetry issues, then session establishment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesession establishment accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The centralized session management system serves as a mediator that simplifies the overall architecture despite its central role. By consolidating session tracking in one location, the system eliminates the need for complex distributed consensus mechanisms that would be required if multiple security elements tried to independently track sessions in an asymmetrical network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security elements independently track sessions in asymmetrical networks, then device autonomy is maintained, but session state information becomes inconsistent across different security elements

Engineering Contradiction:
Improvesecurity element autonomyVSAvoidsession state consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent merges session tracking authority into a single centralized system that maintains the single source of truth for session states. This eliminates inconsistencies that arise when distributed security elements independently track sessions and receive different information due to path asymmetry. The centralized system ensures all security elements receive consistent session state information.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized session management system implements feedback mechanisms where it notifies security elements of session state changes and provides authoritative determinations about session validity. This feedback loop ensures all security elements have consistent, up-to-date information about session states, resolving the inconsistency problem while maintaining system coordination.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8732796B1Addressing security in asymmetrical networks
Publication Date: 2014.05.20 T MOBILE INNOVATIONS LLC
  • US8732796B1 patent drawing
  • US8732796B1 patent drawing
  • US8732796B1 patent drawing

AI summary

Security in an asymmetrical network is addressed. At a security element, a handshake message is received on a path within the asymmetrical network. The handshake message is associated with an attempt to establish a session. A determination is made as to whether there is an entry for the handshake message in a local state table. When there is no entry in the local state table, then an entry is generated in the local state table, a notification of the handshake message is sent to a centralized computing platform that tracks handshake messages received by a plurality of security elements in the asymmetrical network, and the handshake message is allowed to pass along the path. A notification is received from the centralized computing platform that the session associated with the handshake message is allowed, based on associated handshake messages received at the centralized computing platform.