Identity-Based IP Networking with Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer networks are vulnerable to attacks due to their dynamic nature, making it difficult to detect and mitigate malware and unknown threats, leading to reactive security measures that are often ineffective in preventing network breaches.

Innovation Solution

An identity-based internet protocol system that inserts a shim into IP packets to enforce policies and authenticate sources and destinations, reducing anonymous traffic and enhancing network security by hiding machines and infrastructure, thereby reducing the threat surface and enabling proactive anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional networks allow dynamic changes and modifications to devices, then ease of operation is improved, but network security deteriorates due to increased vulnerability to attacks

Engineering Contradiction:
Improveease of adding and modifying devicesVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication and identity verification before allowing devices to join the network. The PEP inserts identity information into IP packets as devices attempt to connect, ensuring that only authenticated devices can participate in network communications before any dynamic changes occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The Policy Enforcement Point (PEP) acts as an intermediary between devices and the network infrastructure. It intercepts IP packets, inserts identity shims, and enforces security policies, mediating all communications to ensure that dynamic device additions and modifications are securely managed without compromising network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If conventional networks allow anonymous traffic, then device complexity is reduced, but the ability to detect and respond to threats deteriorates

Engineering Contradiction:
Improvenetwork architecture simplicityVSAvoidthreat detection capability
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary identity insertion into IP packets at the PEP before traffic enters the network. This preliminary action ensures that every packet carries identifiable source and destination information, enabling continuous monitoring and threat detection without requiring complex changes to existing network devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the identity parameter of network traffic by inserting identity shims into IP packets. This parameter change transforms anonymous traffic into identifiable traffic, enabling security monitoring and threat detection while maintaining compatibility with standard IP networking infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If reactive security measures are used to address malware, then response time is reduced, but effectiveness deteriorates because damage occurs before detection

Engineering Contradiction:
Improveresponse time to threatsVSAvoidsecurity effectiveness
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary authentication and identity verification before devices can compromise the network. By establishing identity information in advance and continuously monitoring authenticated devices, the system enables proactive detection of malicious activities before they can cause damage, rather than reacting after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback monitoring of authenticated devices through identity tracking in IP packets. The PEP and network monitoring systems continuously analyze traffic from known identities, providing real-time feedback that enables detection and response to malicious behaviors as they occur, improving both response time and effectiveness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10630725B2Identity-based internet protocol networking
Publication Date: 2020.04.21 THE MITRE CORPORATION
  • US10630725B2 patent drawing
  • US10630725B2 patent drawing
  • US10630725B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for identity-based internet protocol networking. An embodiment operates by receiving a packet from a device of a secured network. A strength of authentication of the device is determined based on how a user account associated with the device is authenticated. A policy corresponding to the strength of authentication is determined. The packet is transmitted based upon the policy.