Dynamic Authentication Order for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication methods are inefficient for devices incompatible with type-I authentication tests, leading to excessive processing resource consumption and complexity, and require manual configuration and color-coded ports, which are costly and labor-intensive.

Innovation Solution

Dynamically determining the authentication order and mode for devices based on identified categories through data packets exchanged before authentication, altering the sequence of authentication tests and eliminating the need for manual configuration and color-coded ports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If type-I authentication test is repeatedly attempted for devices incompatible with it, then authentication coverage is improved, but processing resource consumption and time increase significantly

Engineering Contradiction:
Improveauthentication coverageVSAvoidauthentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements dynamic authentication order adjustment based on device category identification. The system transitions from a static, fixed authentication sequence to a dynamic one where the authentication order is adapted according to the identified device type, allowing incompatible devices to skip type-I tests and proceed directly to type-II tests, thereby reducing authentication time while maintaining coverage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary device category identification through data packet exchange before initiating the authentication process. This preliminary action enables the system to determine the appropriate authentication sequence in advance, avoiding unnecessary repeated type-I authentication attempts for incompatible devices and reducing overall authentication time.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If type-I authentication test is repeatedly attempted for incompatible devices, then authentication coverage is improved, but processing resource consumption increases

Engineering Contradiction:
Improveauthentication coverageVSAvoidprocessing resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically adjusts the authentication process based on real-time device category identification. By making the authentication sequence adaptive rather than fixed, the system optimizes processing resource allocation by eliminating redundant type-I authentication attempts for devices that are incompatible with this test type.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The preliminary identification of device category through data packet analysis enables the system to pre-determine the appropriate authentication path, preventing wasteful consumption of processing resources on incompatible devices before the actual authentication process begins.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual configuration and color-coded ports are used for different device types, then authentication accuracy is improved, but manufacturing cost and labor intensity increase

Engineering Contradiction:
Improvedevice type identification accuracyVSAvoidmanufacturing cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent replaces the mechanical/physical system of color-coded ports and manual configuration with an automated electronic identification system. The system uses data packet exchange and category identification algorithms to automatically determine device types, eliminating the need for physical port differentiation and manual setup while maintaining accurate device type identification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If manual configuration is required for each port based on device type, then authentication precision is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improveauthentication precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service automatic device type identification through data packet exchange. Devices automatically provide identification information through their data packets, and the system autonomously determines the appropriate authentication sequence without requiring manual configuration, thereby reducing operational complexity while maintaining authentication precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual configuration procedures with automated electronic identification and classification systems, eliminating the need for complex manual setup processes while preserving accurate device type recognition and appropriate authentication sequencing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11258794B2Device category based authentication
Publication Date: 2022.02.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11258794B2 patent drawing
  • US11258794B2 patent drawing
  • US11258794B2 patent drawing

AI summary

Example approaches for authenticating a device are described. In an example, a category, from a plurality of categories, is identified for a device, based on data packets exchanged between the device and a network element. The category is indicative of operational capabilities of the device. Based on the category identified for the device, an authentication order for the device is determined. The authentication order is indicative of a sequence in which a set of authentication tests is to be executed for authentication of the device.