Network Device Authentication via Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack an efficient and automated way to authenticate network devices within communication networks, leading to manual intensive installation processes and potential mistakes or misuse, as traditional digital certificates are not used for device authentication.

Innovation Solution

Issuing unique digital certificates by a certificate authority to network devices, which include identification and public key information, and using RFID tags to store and authenticate these certificates upon connection to the network, allowing devices to verify their authenticity and connect securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual installation and configuration methods are used for network devices, then device authentication can be performed, but the process becomes manually intensive and error-prone

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidinstallation process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network device performs self-authentication by automatically presenting its digital certificate to the authentication server upon connection. The device autonomously verifies its identity without requiring manual configuration or intervention, transforming a manual process into an automated self-service operation that maintains high authentication reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Digital certificates are issued to network devices before they are deployed into the network. This preliminary action of pre-configuring authentication credentials eliminates the need for manual authentication setup during installation, allowing devices to authenticate automatically when connected while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional digital certificates are not used for device authentication, then installation is simpler, but authentication capability and security are insufficient

Engineering Contradiction:
Improveinstallation simplicityVSAvoidauthentication capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces manual mechanical authentication processes with automated cryptographic verification using digital certificates and public key infrastructure. The authentication server automatically verifies device credentials through cryptographic operations, substituting manual procedures with secure automated mechanisms that enhance both simplicity and authentication capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication server acts as an intermediary between network devices and the network infrastructure. It automatically handles the verification of digital certificates and public keys, enabling robust authentication capability while maintaining installation simplicity by abstracting the complex cryptographic verification process from the device and user.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated authentication is implemented, then manual labor is reduced, but system complexity increases

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication server performs multiple functions including digital certificate verification, public key validation, and authentication decision-making within a single integrated system. This multi-functionality consolidates what would otherwise be separate complex components into one unified authentication mechanism, enabling automated high-speed authentication without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8892869B2Network device authentication
Publication Date: 2014.11.18 AVAYA INC
  • US8892869B2 patent drawing
  • US8892869B2 patent drawing
  • US8892869B2 patent drawing

AI summary

The present invention relates to using digital certificates to allow network devices to authenticate themselves upon being accepted into and forming part of a communication network.