Automated Network Identification for Secure Hybrid Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in identifying and connecting isolated networks, particularly in hybrid environments with on-premises and cloud setups, leading to security risks due to unprotected internet traffic between networks.

Innovation Solution

The technology automatically identifies candidate networks based on communication data, such as IP addresses and connection strength, to recommend the creation of virtual private networks (VPNs) for secure communication and improved network administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If networks are kept isolated for security reasons, then security risks are reduced, but network administration efficiency and connectivity are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork administration efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an automated network identification system that acts as an intermediary between isolated networks. This system analyzes communication patterns, identifies candidate networks, and recommends VPN connections without requiring manual network configuration or exposing networks to unnecessary connections, thus maintaining security while improving administration efficiency through automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously monitoring network communication patterns and using this information to automatically identify networks that should be connected. The feedback loop analyzes traffic data, determines candidate networks, and recommends VPN configurations, allowing the system to adapt to changing network relationships while maintaining security boundaries.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual network identification and VPN configuration is performed, then network security can be maintained, but time consumption and administrative effort increase

Engineering Contradiction:
Improvenetwork securityVSAvoidtime for network administration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables self-service by implementing an automated system that performs network identification, analysis, and VPN recommendation without requiring manual intervention. The system autonomously collects communication data, identifies candidate networks based on predefined criteria, and generates VPN configuration recommendations, significantly reducing the time and effort required for network administration while maintaining security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively analyzing network communication patterns and identifying candidate networks before manual configuration is needed. By continuously monitoring and pre-identifying networks that should be connected, the system prepares recommendations in advance, eliminating the need for time-consuming manual network discovery and VPN setup processes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all external communications are monitored for security, then security coverage is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing targeted monitoring rather than uniform surveillance of all external communications. The system focuses analysis on specific communication patterns and networks that meet predefined criteria for potential VPN connections, applying security monitoring selectively to high-priority areas while reducing complexity for lower-priority communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the monitoring process by dividing external communications into distinct categories based on network identification criteria. It separates communications that warrant detailed analysis from those that do not, processing each segment according to its specific security requirements, thereby improving security coverage while managing system complexity through structured segmentation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3635919B1Automatic network identification for enhanced communications administration
Publication Date: 2021.02.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3635919B1 patent drawingFigure 1~3
  • EP3635919B1 patent drawingFigure 4~6
  • EP3635919B1 patent drawingFigure 7~8

AI summary

Described technologies automatically detect candidate networks having external nodes which communicate with nodes of a local network; a candidate external network can be identified even when the external nodes are owned by a different entity than the local network's owner. A list of network addresses which communicated with local network nodes is culled to obtain addresses likely to communicate in the future. A graph of local and external nodes is built, and connection strengths are assessed. A candidate network is identified, based on criteria such as connection frequency and duration, domain membership, address stability, address proximity, and others, using cutoff values that are set by default or by user action. The candidate network identification is then utilized as a basis for improved security though virtual private network establishment, improved bandwidth allocation, improved traffic anomaly detection, or network consolidation, for example.