Dedicated Network Connection Authentication With Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods for securing dedicated network connections between computing resource service providers and customers are inflexible and vulnerable to unauthorized access, relying on manual intervention and cryptographic techniques with exploitable vulnerabilities.

Innovation Solution

Implementing an authentication process using digital signatures generated with symmetric or asymmetric cryptographic algorithms, managed by computer systems, to verify the identity of both the customer and the computing resource service provider, eliminating the need for manual intervention and reducing vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods are used to secure dedicated network connections, then connection security is provided, but the authentication process is inflexible and requires manual intervention

Engineering Contradiction:
Improveconnection securityVSAvoidmanual intervention requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automated authentication where the network devices perform verification of credentials and digital signatures without requiring manual administrator intervention. The authentication service automatically validates credentials against stored information and establishes secure connections, allowing the system to serve itself in the authentication process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures authentication credentials and digital signatures before the actual connection is established. By preparing authentication information in advance and storing it in the authentication service, the system eliminates the need for manual setup during the connection process, making authentication both secure and automated.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional cryptographic techniques are used to secure the connection, then encryption is provided, but vulnerabilities exist that can be exploited for unauthorized access

Engineering Contradiction:
Improveconnection securityVSAvoidcryptographic vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from conventional cryptographic techniques to digital signature-based authentication. This parameter change in the authentication mechanism provides enhanced security by using asymmetric cryptography and digital signatures, which are more resistant to exploitation than traditional symmetric encryption methods.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system replaces conventional cryptographic mechanisms with a digital signature-based authentication service. This substitution introduces a more secure authentication paradigm where digital certificates and asymmetric key pairs replace traditional encryption/decryption approaches, reducing vulnerabilities to known cryptographic attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual authentication processes are used, then security verification is performed, but the process is inflexible and time-consuming

Engineering Contradiction:
Improveauthentication verificationVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication service automatically performs verification of digital signatures and credentials without requiring manual administrator actions. The system self-manages the authentication process by automatically validating credentials against stored information and establishing secure connections, significantly improving authentication speed while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By pre-configuring and storing authentication credentials and digital signatures in the authentication service before connection requests occur, the system enables rapid automated verification. This preliminary preparation eliminates the need for time-consuming manual authentication processes while maintaining rigorous security verification.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If dedicated physical connections are used, then direct network peering is established, but points of susceptibility exist where unauthorized access is possible

Engineering Contradiction:
Improvedirect connection securityVSAvoidphysical access vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication service acts as an intermediary between the connecting network devices. It mediates the authentication process by verifying digital signatures and credentials, providing a layer of security that protects against unauthorized access at physical connection points. This intermediary verification layer secures the dedicated connection without requiring changes to the physical infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12413493B2Network connection automation
Publication Date: 2025.09.09 AMAZON TECH INC
  • US12413493B2 patent drawing
  • US12413493B2 patent drawing
  • US12413493B2 patent drawing

AI summary

A computing resource service provider receives a request from a customer to establish a physical connection between a provider network device and a customer network device in a colocation center. Once the connection has been established, the customer may transmit cryptographic authentication information, through the physical connection, to the provider network device. The provider network device transmits this information to an authentication service operated by the computing resource service provider to verify the authenticity of the information. If the information is authentic, the authentication service may re-configure the provider network device to allow the customer to access one or more services provided by the computing resource service provider. The authentication service may transmit cryptographic authentication information to the customer to verify the identity of the computing resource service provider.