Network Device Authentication Unit for Impersonation Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices lack effective security measures to prevent unauthorized data transmission, particularly in scenarios where the sender network device is compromised, leading to potential impersonation attacks that other devices struggle to detect and mitigate.

Innovation Solution

A network device equipped with an authentication unit that verifies message authentication information and a processing unit that invalidates data if unauthorized transmission is detected, ensuring only authenticated data is transmitted, thereby preventing impersonation attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message authentication is implemented at the sender network device, then security against impersonation attacks is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity against impersonation attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication unit as an intermediary component between the communication interface and the processing logic. This dedicated authentication unit handles message authentication independently, acting as a mediator that verifies sender identity without requiring complex security measures throughout the entire system. The authentication unit receives communication data from the communication interface and performs authentication before the data is processed further, thereby improving security while keeping the overall device complexity manageable through functional separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security measures are deployed at all network devices, then protection against attacks is improved, but implementation cost increases significantly

Engineering Contradiction:
Improveprotection against attacksVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing authentication functionality specifically at the sender network device where impersonation attacks originate, rather than uniformly across all network devices. The authentication unit is strategically placed at the sender side to verify message authenticity before transmission. This localized approach provides effective protection against attacks while avoiding the need for expensive comprehensive security measures at every device in the network, thereby reducing overall implementation cost.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If authentication verification is performed for all incoming data, then detection of unauthorized transmission is improved, but processing time increases

Engineering Contradiction:
Improvedetection of unauthorized transmissionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by performing authentication verification as the first step in the data processing pipeline, before any further processing occurs. The authentication unit verifies the authenticity of incoming communication data immediately upon receipt from the communication interface. This preliminary authentication ensures that unauthorized transmissions are detected early, and legitimate data flows through the system without unnecessary delays, as subsequent processing can proceed in parallel once authentication is confirmed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11134100B2Network device and network system
Publication Date: 2021.09.28 ASTEMO LTD
  • US11134100B2 patent drawing
  • US11134100B2 patent drawing
  • US11134100B2 patent drawing

AI summary

A network device connected via a bus with a plurality of network devices includes: an authentication unit that executes authentication based upon message authentication information included in data transmitted, via the bus, by one of the plurality of network devices acting as a sender device; and a processing unit that invalidates the data upon determining that unauthorized data have been transmitted by the sender device impersonating another network device among the plurality of network devices if the authentication fails.