Configurable Device Fingerprinting for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional endpoint fingerprinting techniques face limitations, particularly in workplaces where multiple devices share the same attributes, leading to incorrect blocking of devices that should be granted access.

Innovation Solution

A method and system for configurable device fingerprinting, where a server stores selected system attributes, extracts relevant information from client devices, generates a unique identifier, and secures communications using tokens, allowing for differentiated identification and access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional endpoint fingerprinting techniques are used to monitor and control network access, then network security is improved, but devices sharing the same attributes are incorrectly blocked

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the device identification process into multiple independent components: device attributes (hardware/software characteristics), location information (network segment, MAC address), and behavioral patterns. By dividing the fingerprinting system into these separate segments that can be individually configured and weighted, the system achieves more precise device differentiation while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters used for device identification from simple attribute matching to a multi-parameter fingerprinting system. It introduces configurable parameters including device attributes, location information, and temporal patterns, allowing the system to adjust identification precision by selecting and weighting different parameters based on security requirements.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If multiple devices share the same attributes in a workplace, then device deployment is simplified, but individual device identification becomes difficult

Engineering Contradiction:
Improvedevice deploymentVSAvoiddevice differentiation
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds new dimensions to device identification beyond basic attributes. It incorporates location information (network segment, MAC address), temporal patterns (usage times, activity patterns), and behavioral characteristics as additional identification dimensions. This multi-dimensional approach enables differentiation of devices with identical attributes by observing them from different dimensional perspectives.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors device behavior, location, and attribute patterns, then uses this feedback to refine device identification. The system learns from observed patterns and adjusts its fingerprinting criteria, enabling it to distinguish between devices with similar attributes through their unique behavioral feedback signatures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11030293B2Method and system for configurable device fingerprinting
Publication Date: 2021.06.08 BEIJING DIDI INFINITY TECH & DEV CO LTD
  • US11030293B2 patent drawing
  • US11030293B2 patent drawing
  • US11030293B2 patent drawing

AI summary

Methods and systems for configurable device fingerprinting and/or achieving communications with enhanced security are disclosed herein. In one example embodiment, a method of configurable device fingerprinting includes storing, at a server, first information regarding one or more selected system attributes, and further includes receiving, at the server, a first signal requesting that a first client device be registered and including system information pertaining to the first client device. Also, the method includes extracting, from the system information, relevant portions of the system information corresponding to the one or more selected system attributes, where the server determines a fingerprint of the first client device based at least in part the relevant portions. Additionally, the method includes generating a first identifier pertaining to the first client device at least indirectly in response to the extracting of the relevant portions, and sending the first identifier for receipt by the first client device.