ICN Authentication Requirement Analysis via Modular Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack a formal mechanism to analyze and determine authentication requirements for Information Centric Network (ICN) services, leading to challenges in verifying if an authentication solution meets the specific requirements of evolving ICN services and devices, due to architectural variations, trust levels, and diverse threat models.

Innovation Solution

A method and system that capture key entities and their interactions in ICN networks, representing authentication requirements by analyzing content delivery options, trust relationships, and potential threat models, using modules to infer valid service flows and constraints for authentication solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If formal mechanism for analyzing authentication requirements is introduced, then authentication solution verification capability is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication solution verification capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication requirement analysis is segmented into distinct functional modules: service specification module captures service parameters, possible service flows representation module models delivery paths, first inference module determines trust levels, second inference module identifies authentication scopes, and valid service flow representation module synthesizes results. This segmentation improves verification capability while managing system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication requirement analysis system that mediates between ICN service specifications and authentication solutions. This intermediary formally analyzes service parameters, trust relationships, and threat models to generate authentication requirements, enabling systematic verification without directly complicating the authentication solution itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive threat models and trust relationships are analyzed, then authentication requirement accuracy is improved, but analysis time increases

Engineering Contradiction:
Improveauthentication requirement accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining trust relationships, authentication scope definitions, and content delivery options in the service specification phase. Possible service flows are pre-represented based on content nature and delivery options. This preliminary structuring enables faster, more accurate authentication requirement analysis without comprehensive real-time evaluation of all threat models.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by representing trust relationships as quantifiable trust levels and authentication scopes as defined parameters. By transforming qualitative security concepts into measurable parameters, the system achieves accurate authentication requirement determination while reducing analysis time through structured parameter evaluation rather than exhaustive threat model exploration.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If flexible support for different architectural paradigms is provided, then service adaptability is improved, but mechanism complexity increases

Engineering Contradiction:
Improveservice adaptabilityVSAvoidmechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication requirement analysis mechanism that supports multiple ICN architectural paradigms (centralized, distributed, hybrid) and various service types (content delivery, publish-subscribe, request-response). The service specification module and inference modules are designed to handle diverse architectures through unified parameter representation, achieving broad adaptability without proportionally increasing mechanism complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts to different architectural paradigms by adjusting its analysis based on service specification parameters. The possible service flows representation and inference modules can reconfigure their analysis approach according to the specific ICN architecture being evaluated, providing flexible support for evolving service sets without requiring separate mechanisms for each paradigm.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9203827B2Methods for determining authentication requirements of information centric network based services and devices thereof
Publication Date: 2015.12.01 INFOSYS LTD
  • US9203827B2 patent drawing
  • US9203827B2 patent drawing
  • US9203827B2 patent drawing

AI summary

A method, device, and non-transitory computer readable medium for determining and representing one or more authentication requirements for at least one valid service flow of one or more information centric network (ICN) based services. This technique involves capturing service specification and storing it in a repository. Then, one or more possible service flows are generated and represented based on the nature of contents, delivery options and preferred architecture. This representation is again modified based on the trust level among functional entities and authentication scope which are inferred from the service specification. The final representation of the service flow shows only the valid inter-connections and operations among functional entities and the service flow is constrained by authentication requirement.