Multi-Plane Threshold Security for APT Deterrence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods, despite using one-time passcode devices and two-factor authentication, are vulnerable to advanced persistent threats (APTs) due to their limitations in providing robust security against sophisticated attacks.

Innovation Solution

Implementing multi-plane threshold security techniques where servers operate in multiple security planes, each implementing a portion of a threshold security protocol, requiring assent from a minimum number of servers to access protected resources, thereby enhancing security through a flexible architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional two-factor authentication using OTP devices is implemented, then basic security against unauthorized access is improved, but the system remains vulnerable to advanced persistent threats (APTs) due to insufficient security depth

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to APTs
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is divided into multiple independent security planes (first plane, second plane, third plane), each implementing separate authentication protocols. This segmentation ensures that compromise of one plane does not necessarily lead to system-wide breach, directly addressing the vulnerability to APTs while maintaining reliable security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-layer authentication to multi-plane authentication, adding dimensional depth to the security architecture. Each plane operates independently and contributes to the overall authentication decision, creating a multi-dimensional security barrier that effectively counters APTs while preserving security reliability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple security planes are implemented to deter APTs, then security robustness is improved, but system complexity increases due to multiple servers and protocols

Engineering Contradiction:
Improvesecurity robustnessVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the authentication system into distinct planes with specific functions, the patent manages complexity through modular design. Each plane handles specific authentication tasks independently, making the overall complex system more manageable and maintainable while achieving enhanced security robustness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The multiple servers in each plane can perform various authentication functions and workloads, providing multi-functionality that justifies the added complexity. The universal design allows flexible configuration and scaling, enabling the system to achieve security robustness without proportionally increasing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If threshold security protocols requiring multiple server assents are implemented, then protection against compromised servers is improved, but authentication time and processing overhead increase

Engineering Contradiction:
Improveprotection against compromised serversVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication checks in earlier planes before proceeding to subsequent planes. This preliminary action filters out obviously unauthorized requests early, reducing the time impact of threshold protocols for legitimate users while maintaining protection against compromised servers through the full multi-plane verification process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements threshold security at appropriate levels - requiring sufficient but not excessive server assents. This partial action approach balances security needs with performance considerations, providing adequate protection against compromised servers without imposing excessive authentication time delays on legitimate operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8782752B1Apparatus and method for multi-plane threshold security
Publication Date: 2014.07.15 EMC IP HLDG CO LLC
  • US8782752B1 patent drawing
  • US8782752B1 patent drawing
  • US8782752B1 patent drawing

AI summary

Servers are configured to operate in two or more threshold security planes with each such threshold security plane implementing at least a portion of a corresponding threshold security protocol involving at least a subset of the servers. The servers are implemented on at least one processing device comprising a processor coupled to a memory. Multiple ones of the servers may be implemented on a single processing device, or each of the servers may be implemented on a separate processing device. At least one of the servers may be part of at least two of the threshold security planes. A given request for a protected resource is processed through each of the planes in order for a corresponding user to obtain access to the protected resource. By way of example, the security planes may comprise two or more of an authentication plane, an access control plane and a resource plane.