Network Device Configuration Verification via Distributed Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security technologies fail to ensure device security by not verifying the configuration of computers accessing the network, leading to potential communication problems and security vulnerabilities due to improper configurations such as outdated software or missing security patches.

Innovation Solution

A configuration certifier generates verification credentials for each device, allowing it to authenticate the configuration of other devices without relying on a central authority, ensuring that devices meet specific security standards before accessing the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central authority verifies the configuration of each computer before allowing network access, then network security is improved, but network performance deteriorates due to bottlenecks

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the centralized verification function into distributed verification capabilities. Each device is segmented into a verifier that can independently verify configuration credentials of other devices. This segmentation eliminates the single-point bottleneck of a central authority while maintaining verification security, allowing parallel verification operations that improve network performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary verification by requiring devices to obtain configuration credentials from a certification authority before attempting network access. This preliminary action ensures that verification is completed in advance, allowing devices to authenticate each other directly during communication without requiring real-time central authority intervention, thus avoiding performance bottlenecks.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If a central authority is required for configuration verification, then verification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveverification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses copying by creating verification credentials that contain configuration information signed by a certification authority. These credentials are copied to devices and can be verified by any verifier using the authority's public key. This copying mechanism maintains verification accuracy through cryptographic validation while simplifying the system by eliminating the need for complex centralized verification processes during device interactions.

Inventive Principle:
Principle #26Copying

3Reliability

If configuration verification is performed continuously through a central authority, then security reliability is improved, but response time increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary configuration verification by requiring devices to obtain signed configuration credentials from a certification authority before network access. This preliminary action ensures security reliability is established in advance, allowing devices to perform fast local verification of credentials during communication without time-consuming real-time central authority involvement, thus reducing response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic re-verification by requiring devices to update their configuration credentials at scheduled intervals or when configuration changes occur. This periodic action maintains security reliability without requiring continuous central authority involvement, allowing devices to operate with verified credentials between update periods, thereby minimizing response time delays.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8024488B2Methods and apparatus to validate configuration of computerized devices
Publication Date: 2011.09.20 CISCO TECHNOLOGY INC
  • US8024488B2 patent drawing
  • US8024488B2 patent drawing
  • US8024488B2 patent drawing

AI summary

A system verifies configuration of a device within a network via an exchange of verification credentials, which are requested, received and authenticated. The verification credentials indicate that a configuration of the device was acceptable at the time of creation of the verification credentials for that device. The verification credentials of the device are obtained through a certifying process. During the certifying process, the credential certifier receives a current device configuration of the device in the network, and evaluates the current device configuration of a device with respect to its role within a network. The verification credentials are issued to the requesting device and stored within a database. The device submits its verification credentials if being requested by the other peer it's communicating with when it enters the network. It also monitors the current device configuration and if there are changes, it invalidates the existing certification credentials and requests new one.