Identity-Based Network Policy Enablement via Intermediary Stamps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intermediaries in communication paths between endpoint peers lack the ability to identify and authenticate users, which compromises security and network traffic processing efficiency, as they rely on existing protocols that do not inherently support user identification and authentication.

Innovation Solution

Modifying handshake messages with an intermediary stamp that allows intermediaries to identify and authenticate endpoint peers by using hash signatures and certificates, enabling enhanced security and identity-based rule application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intermediaries use existing authentication and encryption protocols, then security protection is provided, but intermediaries cannot identify or authenticate endpoint users

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser identification capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the authentication process by introducing an intermediary stamp that separates identity verification from data transmission. The stamp is added to handshake messages independently, allowing intermediaries to verify user identity without disrupting the existing encryption protocol flow.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediary stamp acts as a mediator between endpoint peers and network intermediaries. It carries authentication information that enables routers and switches to verify user identities without requiring endpoint peers to directly authenticate with each other, thus resolving the identification capability gap.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If intermediaries modify handshake messages with intermediary stamps, then intermediary ability to identify and authenticate endpoint peers is enabled, but protocol complexity increases

Engineering Contradiction:
Improveintermediary authentication capabilityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication functionality into the existing handshake message structure by adding an intermediary stamp. This combines identity verification with the established protocol flow, avoiding the need for separate authentication protocols and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The intermediary stamp is prepared and inserted into handshake messages during the initial connection establishment phase. This preliminary action ensures that authentication information is available to all intermediaries before data transmission begins, eliminating the need for complex runtime authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If intermediaries implement identity-based rules on data traffic, then network traffic processing granularity is enhanced, but implementation and enforcement complexity increases

Engineering Contradiction:
Improvenetwork traffic processing granularityVSAvoidrule enforcement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

User identification information is extracted and embedded in the intermediary stamp during the handshake phase. This preliminary preparation allows network intermediaries to apply identity-based rules to subsequent data traffic without performing complex analysis during packet forwarding, significantly simplifying rule enforcement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The intermediary stamp creates a simplified copy of authentication information that can be easily referenced by network intermediaries. Instead of verifying complex cryptographic proofs for each packet, intermediaries can rely on the pre-computed stamp to enforce identity-based policies efficiently.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8301895B2Identity based network policy enablement
Publication Date: 2012.10.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8301895B2 patent drawing
  • US8301895B2 patent drawing
  • US8301895B2 patent drawing

AI summary

Enhanced network data transmission security and individualized data transmission processing can be implemented by intermediaries in a communication path between two endpoint peers individually having the capability to identify and authenticate one or both of the endpoint peers. Communication session establishment, endpoint peer identity processing and authentication and data traffic encryption protocols are modified to allow intermediaries to track the communications between endpoint peers for a particular communication session and obtain information to authenticate the endpoint peers and identify data traffic transmitted between them. Intermediaries can use the identities of one or both of the endpoint peers to enforce identity based rules for processing data traffic between the endpoint peers for a communication session.