Dispersed Access Rights for Network Routing Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face risks due to the concentration of critical access rights and credentials in VPN routers, which can compromise the entire network if compromised, especially in scenarios like remote network connections.

Innovation Solution

A communication system that disperses access rights by using a physical key and router, where neither contains authentication details, and both must be validated by a key-router validation server to establish a VPN connection, ensuring that critical information is only present when both are used together, thus mitigating risks of theft or loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN router contains credentials and authorization privileges, then secure communication link can be established, but network security is compromised if the router is stolen or compromised

Engineering Contradiction:
Improvesecure communication linkVSAvoidnetwork security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments authorization information into multiple parts: a first part is stored in the VPN router and a second part is stored in a separate security device. Both parts are required to reconstruct the full authorization information, preventing compromise if the router is stolen. This segmentation resolves the contradiction by maintaining reliable communication while reducing security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A separate security device acts as an intermediary that holds a portion of the authorization information. This intermediary prevents direct access to complete credentials, allowing secure communication establishment while mitigating the harm of router compromise. The security device mediates between the router and the authorization system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If complete authorization information is stored in one device, then access control is simplified, but the risk of total network compromise increases

Engineering Contradiction:
Improveaccess control managementVSAvoidnetwork compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authorization information is divided into multiple segments stored in different devices (router and security device). This segmentation maintains operational simplicity through automated key management while dramatically reducing the risk of total network compromise, as an attacker would need to compromise multiple devices simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different devices have different roles and store different portions of authorization information locally. The router handles communication functions while the security device handles credential storage, creating localized security zones that reduce overall system risk while maintaining ease of operation through specialized functions.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If VPN router is used for remote network support, then remote communication capability is enabled, but the router becomes a security vulnerability

Engineering Contradiction:
Improveremote network supportVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts the most vulnerable element (complete authorization information) from the VPN router and stores it in a separate security device. This extraction enables the router to maintain remote network support functionality while removing the security vulnerability of storing complete credentials, as the router alone cannot access full authorization without the security device.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4224792B1System for dispersing access rights for routing devices in network
Publication Date: 2024.01.31 HOLMSTROM JOHN
  • EP4224792B1 patent drawingFigure 1
  • EP4224792B1 patent drawingFigure 2
  • EP4224792B1 patent drawingFigure 3

AI summary

A system for dispersing access rights for routing devices in a network comprising a router (4), a key (1) and a key socket (2), and a key-router validation server (27). The router (4) and the physical key (1) must be present and both must be validated by the key-router validation server (27) before the router can establish a VPN network between remote external (37) and internal networks (36). Neither the key nor the router does contain critical information for allowing access to networks. Losing either the key, or the router, does not endanger security of the networks. This is the essence of dispersed access rights.