Network Device API Access Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined networking (SDN) and other SDX technologies, there is a need to control and manage permissions of applications (APPs) accessing APIs to prevent misuse and abuse, as they are developed by third parties and operate outside the controller.

Innovation Solution

A certificate obtaining method and authentication method are implemented, where a network device sends certificate application information to a certificate generation device, generating a certificate that includes operation permissions for APIs, allowing the authentication device to determine if the APP has permission to access specific APIs, thereby controlling and simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the controller provides APIs for user applications to access and control network devices, then the ease of operation and functionality are improved, but the security and control over application permissions deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by performing authentication and permission verification before allowing applications to access controller APIs. The authentication device verifies application credentials and determines operation permissions in advance, establishing a security barrier before API access is granted. This resolves the contradiction by maintaining ease of operation for authorized applications while ensuring security through pre-verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication device as an intermediary between applications and the controller. This mediator verifies application credentials, manages authentication information, and determines operation permissions without requiring the controller to directly handle security checks. This resolves the contradiction by maintaining API accessibility while delegating security control to a specialized intermediary component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional authentication methods are used without integrated permission information, then the authentication process is simpler, but the control over operation permissions deteriorates

Engineering Contradiction:
Improveauthentication process complexityVSAvoidpermission control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent merges authentication verification and permission determination into a single integrated process. The authentication device simultaneously verifies application credentials and determines operation permissions based on the same authentication information, combining two functions into one unified operation. This resolves the contradiction by maintaining simple authentication flow while enabling comprehensive permission control through the merged process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication device performs multiple functions using the same authentication information: it verifies application identity, determines operation permissions, and controls API access. This multi-functional approach resolves the contradiction by maintaining simple authentication mechanics while achieving versatile permission control through the same authentication framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11451531B2Certificate obtaining method, authentication method, and network device
Publication Date: 2022.09.20 HUAWEI TECH CO LTD
  • US11451531B2 patent drawing
  • US11451531B2 patent drawing
  • US11451531B2 patent drawing

AI summary

A certificate obtaining method, an authentication method, and a network device, where a certificate is used for permission authentication when an application APP accesses an application programming interface (API) of a controller. The certificate includes one or more of: (a) information about operation permission of the APP on N application programming interfaces APIs of the controller, (b) identifiers of L APIs that are of the N APIs and that the APP has permission to operate, or (c) identifiers of R APIs that are of the N APIs and that the APP does not have permission to operate.