Network Connection Computer Authentication for Secure Log-on

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face increased administration complexity and data traffic when logging on communication units, especially when multiple network connection computers are involved, and they require security measures like digital signatures and certificates, limiting access to only secured units.

Innovation Solution

A communications system where the network connection computer verifies log-on authorization and forwards a modified request message to the connection handling computer, reducing the complexity for the connection handling computer and allowing insecure units to log on by shifting authentication and authorization checks to the network connection computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication and authorization checks are performed by the connection handling computer, then security is ensured, but administration complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication and authorization function into two parts: network connection computers perform authentication checks (verifying digital signatures and certificates), while connection handling computers perform authorization checks (verifying user profiles). This segmentation reduces the complexity burden on any single system while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network connection computer acts as an intermediary between communication units and the connection handling computer. It performs preliminary authentication checks and forwards only authorized request messages to the connection handling computer, reducing the complexity of administration for the connection handling computer while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple network connection computers are involved in the logging-on process, then communication units from different networks can access the system, but data traffic increases

Engineering Contradiction:
Improveaccess capabilityVSAvoiddata traffic
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

Network connection computers perform authentication and authorization checks before forwarding request messages to the connection handling computer. This preliminary action filters out unauthorized or invalid messages early in the process, reducing the volume of data traffic that needs to be processed by the connection handling computer while maintaining access capability for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication and authorization verification functions from the connection handling computer and places them at the network connection computer level. This extraction reduces the data traffic burden on the connection handling computer by performing necessary checks locally at network boundaries before messages are forwarded.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If communication units without security measures are allowed to log on, then access versatility improves, but system security deteriorates

Engineering Contradiction:
Improveaccess versatilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network connection computer serves as a security intermediary that performs mandatory authentication checks (verifying digital signatures and certificates) on all incoming request messages before allowing access to the connection handling computer. This ensures that even communication units without strong security measures cannot access the system, while maintaining versatility for authorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication checks using digital signatures and certificates before allowing any communication unit to access the connection handling computer. This preliminary anti-action prevents unauthorized access attempts from reaching the connection handling computer, maintaining system security while allowing verified access to authorized users.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8259914B2System and method for a secure log-on to a communications system comprising network connection and connection handling computers
Publication Date: 2012.09.04 UNIFY BETEILIGUNGSVERWALTUNG GMBH & CO KG
  • US8259914B2 patent drawing
  • US8259914B2 patent drawing
  • US8259914B2 patent drawing

AI summary

In one aspect, communication link established from a communication unit to a communications system. A request message is transmitted from a communication unit to the work connection computer and checked with the aid of a user profile of the communication unit, to verify whether the communication unit has log-on authorization. If the verification of the request message is positive, the request message is forwarded from the network connection computer to the connection handling computer in the form of a modified request message. The modified request message is analyzed by the connection handling computer with the aid of an authentication profile of the network connection computer. Once the modified request message has been positively analyzed and the communication unit has been successfully registered, a response message is transmitted from the connection handling computer to the communication unit.