IP Address Authority Validation for Authorized Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems struggle to effectively validate the authority of devices accessing a network based on their IP addresses, leading to potential unauthorized access and security threats.
Innovation Solution
A system and method that utilizes an Assigned Device Address Polling and Tracking (ADAPT) system to maintain a database of authorized device-IP address pairs, allowing data centers to validate device authority by looking up IP addresses of attempting devices and managing lists of connected and disconnected devices to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security schemes (firewalls, intrusion detection systems, password protection) are implemented, then network security is improved, but device complexity and operational overhead increase
Solution Approach 1:
The patent extracts the IP address validation function from traditional complex security systems and implements it as a standalone ADAPT system with a dedicated database of authorized device-IP pairs. This separates the authority validation mechanism from other security layers, reducing overall system complexity while maintaining security effectiveness.
Solution Approach 2:
The system pre-establishes a database of authorized device-IP address pairs before actual network access attempts. By performing the authorization validation in advance and maintaining ready-to-use authorization data, the system eliminates the need for complex real-time authentication protocols during access attempts.
2Ease of operation
If IP-based access control is implemented without a validation system, then ease of operation is improved, but network security deteriorates due to unauthorized access
Solution Approach 1:
The ADAPT system automatically validates device authority by querying the authorized device-IP pairs database without requiring manual authentication interventions. The system self-manages the validation process, comparing incoming device IP addresses against the pre-stored authorized pairs, thereby maintaining operational simplicity while ensuring security.
Solution Approach 2:
The patent introduces an intermediary ADAPT system that sits between the network and data centers, handling all IP address validation requests. This intermediary layer manages the complexity of security validation internally while presenting a simple interface to both devices and data centers, easing operation without compromising security.
3Measurement precision
If a comprehensive database of authorized device-IP pairs is maintained, then measurement precision of device authority is improved, but loss of time for validation increases
Solution Approach 1:
The system pre-populates and maintains a database of authorized device-IP address pairs before validation is needed. By having authorization data ready in advance, the system eliminates the need for time-consuming queries or computations during actual validation, achieving both high precision and fast processing.
Solution Approach 2:
The patent creates a simplified copy of authorization information in the form of device-IP pairs stored in the database. Instead of performing complex real-time authentication, the system uses this pre-created representation to quickly match and validate incoming devices, reducing validation time while maintaining accuracy.
4Reliability
If real-time tracking of connected and disconnected devices is implemented, then reliability of security monitoring is improved, but device complexity increases
Solution Approach 1:
The patent extracts the device tracking function into a separate module within the ADAPT system that specifically manages connected and disconnected device lists. By separating this monitoring function from the core validation logic, the system achieves comprehensive security monitoring without increasing the complexity of the main access control mechanism.
Data Source
AI summary
A system includes one or more network devices. The network devices are configured to: poll one or more devices to obtain a list of Internet Protocol (IP) addresses of User Equipment devices (UEs) that are authorized to access a network; obtain identifier-IP address pairs based on the IP addresses and identifiers (IDs) of the UEs; receive a request from a UE to connect to the network; and use an IP address of the UE to look up a device ID of the UE in the ID-IP address pairs. If the device ID of the UE is in a list of IDs of the UEs, the network devices are configured to permit the UE to establish a connection to the network. Otherwise, the network devices are configured to prevent the UE from establishing a connection to the network.


