Device Fingerprinting for Network Access Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in effectively managing and securing network communications, particularly with the rise of IoT devices, as they struggle to accurately identify device types and apply tailored access policies, leading to security gaps and performance issues due to the difficulty in distinguishing between legitimate and malicious traffic.

Innovation Solution

The implementation of a system that generates a unique device fingerprint based on detected metrics and utilizes a global policy database with machine learning to create and update device access policies, allowing for real-time adaptation and precise policy application, thereby enhancing network security by accurately identifying devices and managing communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security systems are used to manage network communications, then basic security functions are provided, but the systems cannot accurately identify device types and apply tailored access policies, leading to security gaps

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments device identification into multiple independent metrics (device identifier, hardware version, software version, open ports, network protocols, traffic patterns) rather than relying on a single identifier. This segmentation allows the system to capture comprehensive device characteristics and accurately distinguish between different device types, resolving the contradiction between basic security provision and accurate device identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a unique device fingerprint for each device type by combining multiple metrics, analogous to creating a distinctive visual signature. This fingerprint serves as a precise identifier that enables the system to accurately recognize and differentiate device types, thereby improving measurement precision while maintaining reliable network security through tailored access policies.

Inventive Principle:
Principle #32Color changes

2Reliability

If device access policies are manually configured for each device type, then precise security control is achieved, but the complexity of policy management increases significantly

Engineering Contradiction:
Improveaccess policy controlVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically generating device fingerprints from observed network metrics and autonomously creating or updating access policies based on device type identification. The system monitors network traffic, extracts device characteristics, and applies appropriate policies without manual intervention, thereby maintaining precise security control while dramatically reducing policy management complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where the system continuously monitors network communications, identifies device types based on multiple metrics, applies access policies, and refines its understanding over time. This feedback mechanism enables automatic policy adjustment and optimization, resolving the contradiction between precise control and management complexity by making the system adaptive and self-regulating.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If generic access policies are applied to all devices, then policy management is simplified, but security effectiveness decreases due to inability to distinguish legitimate from malicious traffic

Engineering Contradiction:
Improvepolicy management easeVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by creating customized access policies specific to each device type rather than using uniform generic policies. Each device type receives tailored security rules based on its characteristics (IoT device, smartphone, laptop, etc.), enabling the system to maintain ease of operation through automated classification while achieving high security effectiveness through device-specific policy enforcement.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If multiple metrics are collected and analyzed to generate device fingerprints, then device identification accuracy improves, but the processing complexity and computational resources increase

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsystem processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining device fingerprint templates for various device types based on expected metric patterns. When a new device is detected, the system compares observed metrics against these pre-established templates to quickly identify device types, thereby improving identification accuracy while reducing real-time processing complexity through pattern matching rather than complex analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10972461B2Device aware network communication management
Publication Date: 2021.04.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10972461B2 patent drawing
  • US10972461B2 patent drawing
  • US10972461B2 patent drawing

AI summary

Managing network communications is provided. An indication that a network device has been added to a local network is received. In response to receiving the indication that the network device been added to the local network, metrics corresponding to the network device added to the local network are detected. A device fingerprint corresponding to the network device added to the local network is generated based on the detected metrics.