Network Management Apparatus Using Fake Identification to Prevent Unauthorized Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems fail to prevent unauthorized access from terminals compromised by malicious users, as they do not effectively counter unauthorized access using network configuration information.

Innovation Solution

A network management apparatus that generates and manages legitimate and fake identification information for terminals, associating them and registering the fake information to prevent unauthorized access by making it difficult for malicious users to infer legitimate network configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If legitimate identification information is assigned to terminals for network communication, then network connectivity and communication functionality are enabled, but the network configuration information becomes vulnerable to inference and unauthorized access by malicious users

Engineering Contradiction:
Improvenetwork communication functionalityVSAvoidunauthorized access from intruded terminal
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network management apparatus as an intermediary between terminals and the network. This apparatus generates fake identification information that mediates between the terminal's need for network communication and the security requirement to prevent unauthorized access. The fake information acts as a protective layer that prevents direct exposure of legitimate network configuration information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the identification information parameter by generating fake identification information that differs from the legitimate information. This parameter change ensures that even if the fake information is compromised, the legitimate network configuration remains protected. The fake information is designed to be functionally equivalent for communication purposes but semantically different from the real configuration.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network configuration information is made secure through fake information, then unauthorized access is prevented, but the complexity of information management increases

Engineering Contradiction:
Improvenetwork security against unauthorized accessVSAvoidinformation management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network management apparatus automatically generates, manages, and updates fake identification information without requiring manual intervention. The system self-services by maintaining the association between fake and legitimate information, generating new fake information when needed, and ensuring proper configuration distribution to terminals. This automation reduces the operational complexity despite the increased security measures.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If fake identification information is registered to terminals, then it becomes difficult for malicious users to infer legitimate network configuration, but the terminal configuration complexity increases

Engineering Contradiction:
Improvedifficulty for malicious user to infer network configurationVSAvoidterminal configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the terminal itself and places it in the network management apparatus. The terminal only needs to store and use the fake identification information provided by the network management apparatus, while the complex logic of generating and managing fake information resides externally. This extraction reduces the terminal's configuration complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10516665B2Network management apparatus, network management method, and recording medium
Publication Date: 2019.12.24 NEC ASIA PACIFIC PTE LTD
  • US10516665B2 patent drawing
  • US10516665B2 patent drawing
  • US10516665B2 patent drawing

AI summary

A network management apparatus that connects to a terminal by way of a communication apparatus, includes: a legitimate information generation unit configured to generate legitimate identification information that is identification information to identify the terminal on a network that the network management apparatus manages, the legitimate identification information being managed as legitimate information by the network management apparatus; a fake information generation unit configured to generate fake identification information that is different from the legitimate identification information and that cannot be used as it is for communication with another terminal; a management unit configured to manage the legitimate identification information and the fake identification information in association with each other; and a registration unit configured to register the fake identification information to the terminal.