Three-Way Handshake Authentication for IP Network Spoofing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data communication in IP networks faces challenges with impersonation of IP addresses, requiring complex and costly authentication and encryption methods that may not guarantee secure data transmission if keys are leaked or decoded.

Innovation Solution

A method where communication devices in an IP network establish a three-way handshake using unique identification numbers, disconnect, and then re-establish connections based on response signals to validate authenticity, ensuring secure data communication without the need for complex authentication key generation or encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication key generation or encryption methods are used to prevent spoofing, then data transmission security is improved, but system complexity and cost increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from complex encryption systems and implements it through a simplified three-way handshake process using only IP address verification. This separates the essential authentication capability from the cumbersome encryption infrastructure, achieving security through a lightweight mechanism that does not require key management or decryption capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs disposable session identifiers generated during each three-way handshake that are valid only for that specific connection session. These temporary authentication tokens are discarded after use, eliminating the need for long-term key management and reducing the risk associated with key leakage while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If authentication key generation or encryption methods are used to prevent spoofing, then data transmission security is improved, but implementation cost increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service authentication where the network infrastructure itself performs verification of IP addresses during the three-way handshake process. Routers and switches automatically validate whether the source IP address matches the expected destination IP address, eliminating the need for external authentication servers or expensive security appliances.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes existing network infrastructure devices (routers, switches) perform multiple functions including both data forwarding and security authentication. By enabling these universal devices to handle both routing and spoofing prevention, the system avoids the need for dedicated security hardware, reducing overall implementation cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If IP address-based connection is used, then communication simplicity is improved, but vulnerability to spoofing increases

Engineering Contradiction:
Improvecommunication simplicityVSAvoidspoofing vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces feedback mechanisms in the form of acknowledgment packets during the three-way handshake process. Each device verifies the other's identity through bidirectional IP address confirmation, creating a feedback loop that ensures both parties are authentic before establishing communication. This maintains simplicity while adding security through verification feedback.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by proactively verifying IP address authenticity before allowing data transmission to begin. The three-way handshake process performs spoofing prevention checks in advance, blocking potential attacks before they can compromise the communication, thus maintaining simplicity while preventing harm.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10855681B2Data communication method
Publication Date: 2020.12.01 KOGA ELECTRONICS
  • US10855681B2 patent drawing

AI summary

Communication devices to an IP network through communication lines to each of which a unique identification number is assigned and, in each communication device, the identification numbers of other communication devices allowed to communicate with the each communication device are registered, and the communication lines are uniquely connected for data communication by a three-way handshake based on the identification numbers. A communication line activates another communication line. When a connection is established, the connection is disconnected. It is determined at the activated communication line if a response signal from the activating communication line as a response to a call back signal sent to the activating communication line at a predetermined timing arrives, and it is determined at the activating communication line if a call back signal from the activated communication line arrives. Data communication is performed only when both the activating and activated communication lines are validated.