Network Access Protection via Hardware Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems are vulnerable to unauthorized access due to reliance on password-based authentication methods, which can be easily compromised, and require additional hardware for enhanced security.

Innovation Solution

A system that combines hardware fingerprints with traditional user identification/authentication information to authenticate access attempts, using an Access Management Application to create an access policy domain with authentication and authorization rules, ensuring secure access to network resources without additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used, then ease of operation is improved, but reliability is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines hardware fingerprint identification with traditional password-based authentication methods to create a multi-factor authentication system. The access management application integrates both authentication approaches, requiring users to provide both password credentials and hardware-specific fingerprint data, thereby merging two authentication mechanisms to achieve enhanced security while maintaining operational ease.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If hardware security devices are added, then reliability is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system utilizes existing hardware components already present in client devices (such as CPU identifiers, memory configurations, and device serial numbers) to generate unique hardware fingerprints. Instead of requiring additional dedicated security hardware, the invention makes the existing hardware components serve the security function by having the access management application automatically collect and process identification data from these existing components.

Inventive Principle:
Principle #25Self-service

3Device complexity

If traditional authentication methods are used, then device complexity is minimized, but reliability is worsened

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The access management application serves as an intermediary component that bridges traditional authentication methods with hardware-based identification. This intermediary software layer collects hardware identification data, processes it through fingerprint algorithms, and integrates it with existing authentication protocols, thereby enhancing security without requiring fundamental changes to the underlying system architecture or existing authentication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9047458B2Network access protection
Publication Date: 2015.06.02 DEVICE AUTHORITY LTD
  • US9047458B2 patent drawing
  • US9047458B2 patent drawing
  • US9047458B2 patent drawing

AI summary

A system or method for network access protection executes steps for receiving, at a server, an access request for access to at least one network resource from a client machine, the access request including account authentication information comprising an account identifier and password, obtaining a client machine identifier from the client machine in response to receiving the request for access, and controlling access to the network resource in response to the access request by authorizing access to the network resource for the access request if the client machine identifier matches a registered machine identifier that is registered for use with the account authentication information and the account authentication information matches registered information for a valid account, but denying access to the network resource if the client machine identifier does not match a registered client machine identifier that is registered for use with the account authentication information.