Intermediate Host Access Control Using Ephemeral Authenticators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network systems face challenges in managing certificates and keys due to their widespread use, leading to issues such as expired access rights, long-lasting connections, and difficulty in tracking authenticators across various hosts, especially in virtualized environments and cloud computing, which can compromise security.

Innovation Solution

An intermediate device is introduced between hosts and devices, processing access requests, obtaining ephemeral authenticators, and monitoring their usage based on predefined conditions to ensure secure and controlled access, including managing certificate validity and session lengths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates and keys are widely used for security, then security is improved, but device complexity and management difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An intermediate device is introduced between user devices and hosts to manage authenticators. This intermediary handles the complexity of certificate distribution, monitoring, and revocation centrally, while user devices and hosts maintain simpler security configurations. The intermediate device receives authenticator distribution requests, generates or selects authenticators, distributes them to authorized devices, and monitors their usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediate device serves multiple functions: it acts as a certificate authority, an authentication server, a monitoring system, and a revocation mechanism all in one. This multi-functional approach consolidates what would otherwise require separate systems, reducing overall system complexity while maintaining comprehensive security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Duration of action of moving object

If long-lasting connections are maintained, then service continuity is improved, but security risk increases due to potential unauthorized access

Engineering Contradiction:
Improveconnection durationVSAvoidunauthorized access risk
Core Design Contradiction:
Duration of action of moving objectVSObject-affected harmful factors

Solution Approach 1:

The intermediate device continuously monitors authenticator usage and connection status, providing feedback to determine when to revoke authenticators or terminate connections. The system tracks whether authenticators are being used appropriately and whether connections remain authorized, automatically taking corrective action when anomalies are detected or authorized time periods expire.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system implements periodic monitoring and automatic revocation of authenticators after specified time periods or usage conditions. Instead of maintaining connections indefinitely, the system periodically verifies authorization and automatically terminates connections or revokes authenticators when predetermined time limits are reached or unauthorized activity is detected.

Inventive Principle:
Principle #19Periodic action

3Reliability

If comprehensive monitoring of authenticator usage is implemented, then security control is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediate device centralizes monitoring functions, acting as a mediator between user devices and hosts. All authenticator usage flows through this intermediary, which logs and analyzes usage patterns centrally rather than requiring distributed monitoring across multiple devices. This concentrates processing requirements in one location, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system automatically detects anomalies, verifies authorization, and takes corrective actions without requiring manual intervention. The intermediate device self-manages the monitoring process, automatically comparing usage patterns against authorized parameters and initiating revocation or alert procedures when violations are detected, reducing the need for complex manual monitoring infrastructure.

Inventive Principle:
Principle #25Self-service

4Reliability

If ephemeral authenticators with short validity are used, then security is improved by reducing long-lasting connection risks, but authentication frequency and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically issues new authenticators at predetermined intervals or after specific usage thresholds are reached. This periodic re-authentication mechanism ensures short validity periods for each authenticator while automating the process to minimize user burden. The intermediate device manages the timing and distribution of successive authenticators, maintaining security without requiring manual reconfiguration.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3328024B1Accessing hosts in a computer network
Publication Date: 2026.01.07 SSH COMMUNICATIONS SECURITY
  • EP3328024B1 patent drawingFigure 1
  • EP3328024B1 patent drawingFigure 2
  • EP3328024B1 patent drawingFigure 3

AI summary

A security function is provided by an intermediate device located between hosts and devices requesting for access to the hosts in a computerized network. The intermediate device receives a request for access to a host, and obtains at least one authenticator for use in the requested access to the host. The intermediate device then monitors for communications that use the at least one authenticator.