Host-Based Credential Agent for Network Traffic Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks are vulnerable to malicious remote entities due to subverted or modified local trust databases, leading to trust being placed in non-trustworthy communications and remote locations.

Innovation Solution

A system comprising a host-based credential management agent, a trusted credential database, and an authorization server, which intercepts network traffic, verifies credentials, and cryptographically signs network traffic information to authorize access, preventing communication with untrusted remote computers through a firewall system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local trust databases are used to verify remote entities, then network communication can proceed without centralized authorization, but the trust database may be subverted or modified by malicious users leading to placement of trust in non-trustworthy entities

Engineering Contradiction:
Improvenetwork communication convenienceVSAvoidtrust database integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a centralized authorization server as an intermediary between the host-based credential management agent and the trusted credential database. The authorization server verifies credentials and signs network traffic information, acting as a mediator that prevents direct access to and potential subversion of the trust database while maintaining authentication functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the trust verification function into separate components: the host-based credential management agent that intercepts network traffic, the authorization server that verifies credentials, and the trusted credential database that stores reference information. This segmentation isolates the critical trust database from direct access while maintaining verification capabilities

Inventive Principle:
Principle #1Segmentation

2Reliability

If connection-level authentication and authorization are implemented by intercepting and signing network traffic, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization server performs multiple functions: verifying credentials against the trusted credential database, signing network traffic information with an authorization server key, and authorizing network access. This multi-functionality consolidates security operations into a single component, managing complexity while enhancing security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The firewall system automatically inspects network traffic information and rejects any traffic not signed with the authorization server key without requiring manual intervention. The host-based credential management agent autonomously intercepts and transmits network requests for authorization, enabling self-service security enforcement

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8661246B1System and method for protecting certificate applications using a hardened proxy
Publication Date: 2014.02.25 ROCKWELL COLLINS INC
  • US8661246B1 patent drawing
  • US8661246B1 patent drawing
  • US8661246B1 patent drawing

AI summary

A system for preventing computer software from communicating from a user computer in a network to untrusted remote computers. A host-based credential management agent is operably connected to a user computer for intercepting network traffic information from the user computer and transmitting a network request including credentials of the remote computer and the network traffic information. A trusted credential database contains information identifying trusted entities and corresponding cryptographic certificates. A server cooperates with the management agent for i) verifying whether the user computer in the network request should have network access, and ii) cryptographically signing the intercepted network traffic information with an authorization server key, to authorize network access for the intercepted information. A firewall is operably connected to the user computer and the authorization server. It is configured to inspect the traffic information from the user computer and reject any traffic information not signed with the key.