Network Device Configuration Verification via Distributed Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security technologies fail to ensure device security by not verifying the configuration of computers accessing the network, leading to potential communication problems and security vulnerabilities due to improper configurations such as outdated software or missing security patches.
Innovation Solution
A configuration certifier generates verification credentials for each device, allowing it to authenticate the configuration of other devices without relying on a central authority, ensuring that devices meet specific security standards before accessing the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central authority verifies the configuration of each computer before allowing network access, then network security is improved, but network performance deteriorates due to bottlenecks
Solution Approach 1:
The patent divides the centralized verification function into distributed verification capabilities. Each device is segmented into a verifier that can independently verify configuration credentials of other devices. This segmentation eliminates the single-point bottleneck of a central authority while maintaining verification security, allowing parallel verification operations that improve network performance.
Solution Approach 2:
The patent implements preliminary verification by requiring devices to obtain configuration credentials from a certification authority before attempting network access. This preliminary action ensures that verification is completed in advance, allowing devices to authenticate each other directly during communication without requiring real-time central authority intervention, thus avoiding performance bottlenecks.
2Measurement precision
If a central authority is required for configuration verification, then verification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent uses copying by creating verification credentials that contain configuration information signed by a certification authority. These credentials are copied to devices and can be verified by any verifier using the authority's public key. This copying mechanism maintains verification accuracy through cryptographic validation while simplifying the system by eliminating the need for complex centralized verification processes during device interactions.
3Reliability
If configuration verification is performed continuously through a central authority, then security reliability is improved, but response time increases
Solution Approach 1:
The patent implements preliminary configuration verification by requiring devices to obtain signed configuration credentials from a certification authority before network access. This preliminary action ensures security reliability is established in advance, allowing devices to perform fast local verification of credentials during communication without time-consuming real-time central authority involvement, thus reducing response time.
Solution Approach 2:
The patent implements periodic re-verification by requiring devices to update their configuration credentials at scheduled intervals or when configuration changes occur. This periodic action maintains security reliability without requiring continuous central authority involvement, allowing devices to operate with verified credentials between update periods, thereby minimizing response time delays.
Data Source
AI summary
A system verifies configuration of a device within a network via an exchange of verification credentials, which are requested, received and authenticated. The verification credentials indicate that a configuration of the device was acceptable at the time of creation of the verification credentials for that device. The verification credentials of the device are obtained through a certifying process. During the certifying process, the credential certifier receives a current device configuration of the device in the network, and evaluates the current device configuration of a device with respect to its role within a network. The verification credentials are issued to the requesting device and stored within a database. The device submits its verification credentials if being requested by the other peer it's communicating with when it enters the network. It also monitors the current device configuration and if there are changes, it invalidates the existing certification credentials and requests new one.


