Network Interface Device Secure Remote Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network interface devices lack a secure method for remotely and securely modifying their function sets without requiring user interaction or specialized hardware, posing challenges for end-users and vendors in upgrading functionality and managing configuration settings.

Innovation Solution

A network interface device that receives configuration instructions over a network, authenticates them using an authentication key, and selectively enables or disables functions based on trusted entity verification, employing cryptographic protocols to ensure secure communication and modification of its function set.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firmware update methods are used to enable or disable functions, then product functionality can be modified, but security is compromised due to lack of authenticated update channels and user technical skill requirements

Engineering Contradiction:
Improveproduct functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication of the communication channel before allowing firmware updates or function modifications. An authentication credential is established in advance between the network interface device and the communication device, ensuring that only authenticated entities can modify device functions, thus preventing unauthorized access while enabling legitimate functionality changes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication credential as an intermediary mechanism between the network interface device and the communication device. This credential acts as a mediator that verifies the identity and authority of the communication device, allowing secure function modification without requiring direct trust between the user and the device, thereby resolving the security concern while maintaining adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If programmable chip registers are reset to modify functions, then function configuration can be changed, but device complexity increases due to requirement of specialist hardware and product return

Engineering Contradiction:
Improvefunction configurationVSAvoidspecialist hardware requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical approach of resetting chip registers with specialist hardware with a software-based authenticated communication approach. Instead of requiring physical hardware manipulation and product returns, the system uses cryptographic authentication credentials transmitted over a network to securely configure device functions, eliminating the need for complex specialist hardware while maintaining configuration adaptability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The network interface device is designed to autonomously authenticate communication devices and apply function configurations without requiring external specialist intervention. The device can independently verify authentication credentials and modify its own function set based on authenticated commands, eliminating the need for users to return products to vendors for configuration changes.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If end user interaction is required for firmware updates, then functionality can be modified, but ease of operation deteriorates due to unknown technical skill levels

Engineering Contradiction:
Improvefunctionality modificationVSAvoiduser interaction requirement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system enables the network interface device to autonomously perform authentication and function configuration based on pre-established credentials. The communication device can initiate authenticated commands without requiring the end user to understand technical procedures, and the network interface device automatically processes these commands, making functionality modification easy while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication credential is established in advance between the network interface device and the communication device before any function modifications are attempted. This preliminary authentication step eliminates the need for end users to perform complex technical operations during updates, as the system has already verified the authority of the communication device, thereby improving ease of operation while preserving adaptability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2288077B1Secure creation of a virtual network interface
Publication Date: 2016.11.02 SOLARFLARE COMMUNICATIONS INC
  • EP2288077B1 patent drawingFigure 1~2
  • EP2288077B1 patent drawingFigure 3~4

AI summary

A network interface device providing a set of functions in hardware and being operable in first and second modes: in a first mode, the network interface device being configured to operate with a selected configuration of the set of functions; and in a second mode, the network interface device being operable to select a particular configuration of the set of functions in accordance with configuration instructions received at the network interface device; the network interface device being configured to, on receiving a network message having one or more predetermined characteristics and comprising an authentication key and one or more configuration instructions defining a particular configuration of the set of functions: verify the authentication key; and if the authentication key is successfully verified, select the particular configuration of the set of functions defined in the configuration instructions of the network message.