Interface Discovery Authentication in Name-Based Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In content-centric networks, unsolicited messages from unregistered interfaces are often dropped by nodes, leading to the loss of valid messages due to unknown source identifiers, which can result in communication disruptions and potential security threats.

Innovation Solution

An interface discovery and authentication system that generates a control message with the source identifier and local interface information, allowing the routing agent to authenticate and configure a new channel, enabling data forwarding and logging for administrative actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a node does not accept unsolicited messages from unregistered interfaces, then security is improved and attack impact is minimized, but valid messages from peer nodes are dropped causing communication disruptions

Engineering Contradiction:
ImprovesecurityVSAvoidmessage delivery
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication and channel configuration actions before accepting messages. When an unregistered interface sends a message, the system initiates an authentication process and channel setup procedure in advance, rather than rejecting the message outright. This allows valid messages to be processed after verification while maintaining security against unauthorized communications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication and channel management mechanism between the unregistered interface and the message processing system. This intermediary layer verifies the legitimacy of unsolicited messages, authenticates source identifiers, and establishes communication channels before allowing message delivery. This mediator resolves the contradiction by filtering out malicious messages while permitting valid communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all nodes are coordinated to establish communication channels among themselves, then message delivery reliability is improved, but system complexity and coordination requirements increase

Engineering Contradiction:
Improvemessage deliveryVSAvoidcoordination mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service mechanisms where nodes automatically authenticate and establish channels with unregistered interfaces without requiring manual coordination. When a message arrives from an unregistered interface, the receiving node autonomously initiates authentication, verifies the source identifier, and configures the communication channel. This eliminates the need for complex pre-coordination protocols while ensuring reliable message delivery.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The channel configuration system is made dynamic rather than static. Instead of requiring all nodes to pre-establish fixed communication channels through complex coordination, the system dynamically creates and configures channels on-demand when messages arrive from unregistered interfaces. This dynamic approach reduces initial system complexity while maintaining message delivery reliability through automated authentication and channel setup.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If unsolicited messages are dropped without authentication, then security threats are minimized, but communication flexibility and peer node connectivity are reduced

Engineering Contradiction:
Improvesecurity threatsVSAvoidcommunication flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system applies partial authentication action - not all unsolicited messages are rejected, but only those that fail authentication. Messages from authenticated sources are accepted, while unauthenticated messages are dropped. This partial approach maintains security by filtering out threats while preserving communication flexibility for legitimate peer nodes that can successfully authenticate.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary authentication checks on unsolicited messages before allowing them through. By verifying source identifiers and establishing authenticated channels in advance, the system creates a protective barrier against security threats while enabling flexible communication for legitimate messages. This preliminary anti-action filters harmful messages while preserving adaptability for authorized communications.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10212196B2Interface discovery and authentication in a name-based network
Publication Date: 2019.02.19 CISCO TECHNOLOGY INC
  • US10212196B2 patent drawing
  • US10212196B2 patent drawing
  • US10212196B2 patent drawing

AI summary

One embodiment provides an interface discovery system that facilitates interface discovery and authentication. During operation, the system receives a message from an unregistered interface via a local interface of a link adapter. The message can include a name. If the system determines that a source identifier of the message is not configured for a channel, the system generates a control message comprising the source identifier and an identifier of the local interface and sends the control message via a transport stack of the system.