Multi-Plane Threshold Security for APT Deterrence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods, despite using one-time passcode devices and two-factor authentication, are vulnerable to advanced persistent threats (APTs) due to their limitations in providing robust security against sophisticated attacks.
Innovation Solution
Implementing multi-plane threshold security techniques where servers operate in multiple security planes, each implementing a portion of a threshold security protocol, requiring assent from a minimum number of servers to access protected resources, thereby enhancing security through a flexible architecture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional two-factor authentication using OTP devices is implemented, then basic security against unauthorized access is improved, but the system remains vulnerable to advanced persistent threats (APTs) due to insufficient security depth
Solution Approach 1:
The authentication system is divided into multiple independent security planes (first plane, second plane, third plane), each implementing separate authentication protocols. This segmentation ensures that compromise of one plane does not necessarily lead to system-wide breach, directly addressing the vulnerability to APTs while maintaining reliable security protection.
Solution Approach 2:
The patent transitions from traditional single-layer authentication to multi-plane authentication, adding dimensional depth to the security architecture. Each plane operates independently and contributes to the overall authentication decision, creating a multi-dimensional security barrier that effectively counters APTs while preserving security reliability.
2Reliability
If multiple security planes are implemented to deter APTs, then security robustness is improved, but system complexity increases due to multiple servers and protocols
Solution Approach 1:
By segmenting the authentication system into distinct planes with specific functions, the patent manages complexity through modular design. Each plane handles specific authentication tasks independently, making the overall complex system more manageable and maintainable while achieving enhanced security robustness.
Solution Approach 2:
The multiple servers in each plane can perform various authentication functions and workloads, providing multi-functionality that justifies the added complexity. The universal design allows flexible configuration and scaling, enabling the system to achieve security robustness without proportionally increasing operational complexity.
3Reliability
If threshold security protocols requiring multiple server assents are implemented, then protection against compromised servers is improved, but authentication time and processing overhead increase
Solution Approach 1:
The system performs preliminary authentication checks in earlier planes before proceeding to subsequent planes. This preliminary action filters out obviously unauthorized requests early, reducing the time impact of threshold protocols for legitimate users while maintaining protection against compromised servers through the full multi-plane verification process.
Solution Approach 2:
The patent implements threshold security at appropriate levels - requiring sufficient but not excessive server assents. This partial action approach balances security needs with performance considerations, providing adequate protection against compromised servers without imposing excessive authentication time delays on legitimate operations.
Data Source
AI summary
Servers are configured to operate in two or more threshold security planes with each such threshold security plane implementing at least a portion of a corresponding threshold security protocol involving at least a subset of the servers. The servers are implemented on at least one processing device comprising a processor coupled to a memory. Multiple ones of the servers may be implemented on a single processing device, or each of the servers may be implemented on a separate processing device. At least one of the servers may be part of at least two of the threshold security planes. A given request for a protected resource is processed through each of the planes in order for a corresponding user to obtain access to the protected resource. By way of example, the security planes may comprise two or more of an authentication plane, an access control plane and a resource plane.


