Gateway Data Flow Control via Layered Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control systems face limitations in accurately controlling network access without additional procedures in universal IP communication environments, particularly when IP uniqueness is ensured, as they rely on IP addresses for identification, which restricts the ability to control layer 3 (network layer) communication and implicitly trust data packets processed by the operating system.
Innovation Solution
A system and method that include a gateway and service server with a processor configured to receive data packets, identify authorized data flows, inspect authentication information, and insert data flow identification into the application processing layer, enabling precise control and authentication of data packets across layers, thereby bypassing the need for tunneling generation and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IP address-based identification is used for network access control, then network communication can be established using standard IP protocols, but the system cannot accurately control network access without additional procedures like tunneling generation
Solution Approach 1:
The system segments the network control function into two parts: the operating system handles standard IP communication at layer 3, while the application processing layer implements authentication and authorization control at layer 7. This segmentation allows each layer to perform its specialized function without interfering with the other, resolving the contradiction between using standard IP protocols and achieving accurate access control.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that acts as a mediator between the OS network stack and application layer. This intermediary verifies communication targets using certificates and authentication information before allowing data transmission, enabling accurate access control without requiring tunneling or modifying standard IP communication protocols.
2Reliability
If tunneling generation is added to process authenticated data flows, then network access control accuracy is improved, but the system complexity and additional procedures increase
Solution Approach 1:
The patent extracts the authentication and authorization control logic from the traditional tunneling approach and implements it directly in the application processing layer. By taking out the essential control function (authentication verification) and placing it where it is most effective (layer 7), the system achieves accurate access control without the overhead of tunneling protocols.
Solution Approach 2:
The application processing layer performs self-service authentication by verifying certificates and authentication information directly. Instead of relying on external tunneling mechanisms to enforce access control, the system enables the application layer to autonomously verify communication targets and control data flows, simplifying the overall system architecture.
3Measurement precision
If the application layer controls layer 3 communication, then precise data flow control is achieved, but the application cannot directly control OS-level network processing
Solution Approach 1:
The system implements a feedback mechanism where the application processing layer sends control instructions to the OS network stack and receives status information in return. This feedback loop allows the application layer to precisely control data flows by monitoring authentication results and adjusting transmission accordingly, effectively bridging the control gap between layers.
Solution Approach 2:
The patent implements preliminary authentication actions at the application layer before data transmission begins. By pre-verifying communication targets and establishing authorized data flows in advance, the application layer can exercise precise control over subsequent network communications without needing to directly manipulate OS-level network processing during data transmission.
Data Source
AI summary
Disclosed is a gateway which includes a communication circuit, a memory, and a processor operatively connected with the communication circuit and the memory. The processor receives a data packet of a node through a network processing layer, identifies whether there is data flow corresponding to the data packet of the node and authorized from an external server, inspects authentication information of the data packet, when there is a need to inspect the authentication information of the data packet based on authentication information included in the data flow, and inserts and forwards data flow identification information capable of being identified by an application processing layer into the data packet to the application processing layer.


