Network Authentication via Statistical Object Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies face challenges in efficiently authenticating network traffic in arbitrary topologies without impacting network performance, particularly when security appliances need to be in the data path, and managing distributed cryptographic keys becomes complex.

Innovation Solution

A peer authentication system that includes a peer authentication driver on network endpoint devices, which monitors IP packets for TCP SYN bits and sends them to an authentication device for secure authentication using Statistical Object Identification (SOI) or Transport Access Control (TAC), allowing subsequent packets to bypass the authentication device, thus not requiring the appliance to be in the network data path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functions are deployed on network appliances in the data path, then network security policy enforcement is achieved, but network performance is impacted due to bottleneck effects

Engineering Contradiction:
Improvenetwork security policy enforcementVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary authentication device that operates outside the main data path. This device receives authentication requests from endpoint security software, performs cryptographic verification, and returns authentication results. By moving the security enforcement point from the network path to the endpoint, the system maintains security policy enforcement while eliminating the performance bottleneck that would occur if all traffic passed through a central security appliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If endpoint security technologies use local cryptographic keys, then authentication can be performed locally, but key distribution and protection becomes complex and difficult to maintain

Engineering Contradiction:
Improvelocal authentication capabilityVSAvoidkey distribution and protection
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key management function from the endpoint devices and centralizes it in the authentication device. Endpoint security software retains the ability to perform local authentication operations, but the actual cryptographic keys are stored and managed exclusively on the authentication device. This extraction allows endpoints to maintain authentication capability without bearing the complexity of key distribution, storage, and protection.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If network resources are deployed arbitrarily throughout the network without centralized planning, then network growth is flexible, but achieving policy enforcement points becomes difficult without costly network re-architecture

Engineering Contradiction:
Improvenetwork growth flexibilityVSAvoidpolicy enforcement implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service architecture where endpoint devices autonomously perform security functions locally through embedded security software. Each endpoint independently communicates with the authentication device, performs local authentication, and enforces security policies without requiring centralized network infrastructure or specific network topology arrangements. This self-service model allows network resources to be deployed flexibly while maintaining policy enforcement capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11095687B2Network security system using statistical object identification
Publication Date: 2021.08.17 INVISINET TECHNOLOGIES LLC
  • US11095687B2 patent drawing
  • US11095687B2 patent drawing
  • US11095687B2 patent drawing

AI summary

Apparatus to enforce network policy based on identity authentication at a network endpoint device by offloading the authentication to a network attached authentication devices is disclosed. The authentication device may use Statistical Object Identification to perform the authentication. The present invention greatly reduces the resources needed by the network endpoint device to perform the authentication and eliminates the topological restrictions found in traditional network appliance based approaches.