Identity-Based IP Networking with Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer networks are vulnerable to attacks due to their dynamic nature, making it difficult to detect and mitigate malware and unknown threats, leading to reactive security measures that are often ineffective in preventing network breaches.
Innovation Solution
An identity-based internet protocol system that inserts a shim into IP packets to enforce policies and authenticate sources and destinations, reducing anonymous traffic and enhancing network security by hiding machines and infrastructure, thereby reducing the threat surface and enabling proactive anomaly detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional networks allow dynamic changes and modifications to devices, then ease of operation is improved, but network security deteriorates due to increased vulnerability to attacks
Solution Approach 1:
The system performs preliminary authentication and identity verification before allowing devices to join the network. The PEP inserts identity information into IP packets as devices attempt to connect, ensuring that only authenticated devices can participate in network communications before any dynamic changes occur.
Solution Approach 2:
The Policy Enforcement Point (PEP) acts as an intermediary between devices and the network infrastructure. It intercepts IP packets, inserts identity shims, and enforces security policies, mediating all communications to ensure that dynamic device additions and modifications are securely managed without compromising network security.
2Device complexity
If conventional networks allow anonymous traffic, then device complexity is reduced, but the ability to detect and respond to threats deteriorates
Solution Approach 1:
The system performs preliminary identity insertion into IP packets at the PEP before traffic enters the network. This preliminary action ensures that every packet carries identifiable source and destination information, enabling continuous monitoring and threat detection without requiring complex changes to existing network devices.
Solution Approach 2:
The system changes the identity parameter of network traffic by inserting identity shims into IP packets. This parameter change transforms anonymous traffic into identifiable traffic, enabling security monitoring and threat detection while maintaining compatibility with standard IP networking infrastructure.
3Loss of time
If reactive security measures are used to address malware, then response time is reduced, but effectiveness deteriorates because damage occurs before detection
Solution Approach 1:
The system performs preliminary authentication and identity verification before devices can compromise the network. By establishing identity information in advance and continuously monitoring authenticated devices, the system enables proactive detection of malicious activities before they can cause damage, rather than reacting after compromise occurs.
Solution Approach 2:
The system implements continuous feedback monitoring of authenticated devices through identity tracking in IP packets. The PEP and network monitoring systems continuously analyze traffic from known identities, providing real-time feedback that enables detection and response to malicious behaviors as they occur, improving both response time and effectiveness.
Data Source
AI summary
Disclosed herein are system, method, and computer program product embodiments for identity-based internet protocol networking. An embodiment operates by receiving a packet from a device of a secured network. A strength of authentication of the device is determined based on how a user account associated with the device is authenticated. A policy corresponding to the strength of authentication is determined. The packet is transmitted based upon the policy.


