Network Rights Descriptors for Packet Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network switching technologies lack effective methods to manage and control user applications across multiple layers of the OSI model, leading to security vulnerabilities and unauthorized network utilization.

Innovation Solution

Implementing network rights descriptors that include application, content, and enterprise rights within data packets, which are processed by multiport network devices to authorize or discard packets based on predefined policies, ensuring only authorized traffic uses network resources and enforcing licensing agreements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network switching technologies are used, then network traffic can be transmitted, but security vulnerabilities and unauthorized network utilization occur due to lack of effective management and control methods

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network packet management by inserting hierarchical descriptors (application rights descriptor, content rights descriptor, enterprise rights descriptor) at different OSI layers into data packets. This segmentation allows granular control and authentication at multiple levels (application, content, enterprise) rather than treating all traffic uniformly, thereby improving security without requiring complete system redesign

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network descriptors as intermediary elements that mediate between the software application and the network device. These descriptors carry authentication information and rights metadata through the packet, enabling the network device to enforce policies without direct complex interaction with applications, thus improving security while managing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network rights descriptors are inserted in each data packet, then authorized traffic can be controlled and spoofed packets prevented, but processing overhead increases

Engineering Contradiction:
Improvepacket authentication accuracyVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having software applications insert their application rights descriptors into data packets before transmission. This pre-insertion of authentication information allows network devices to perform rapid descriptor matching without complex real-time analysis, improving both authentication accuracy and processing efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes packet parameters by adding structured descriptor fields with specific formats (application rights descriptor, content rights descriptor, enterprise rights descriptor). These standardized parameter changes enable efficient matching and comparison at network devices, balancing authentication rigor with processing speed

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multi-layer OSI model processing is implemented, then comprehensive network control is achieved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvenetwork control coverageVSAvoidswitching device complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by designing network descriptors that operate across multiple OSI layers (application layer 7, presentation layer 6, network layer 3, data link layer 2). A single descriptor structure handles authentication, authorization, and policy enforcement functions across different protocol layers, increasing adaptability without proportionally increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a new dimension to network control by inserting descriptor metadata alongside traditional packet data. This dimensional addition (descriptor layer) enables comprehensive multi-layer control while keeping the underlying switching infrastructure relatively simple, as descriptors are processed as additional packet attributes rather than requiring complete protocol stack recreation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7647410B2Network rights management
Publication Date: 2010.01.12 SANDVINE SWEDEN AB
  • US7647410B2 patent drawing
  • US7647410B2 patent drawing
  • US7647410B2 patent drawing

AI summary

Methods and apparatus, including computer program products, implement techniques of processing data packets in a computer network. The computer network includes a multiport network device and a computer executing a software application. The multiport network device is configured to receive data packets to be transmitted using the computer network and the network device stores one or more authorized network descriptors. The software application generates data packets to be transmitted to the computer network through the network device. The software application registers the network rights descriptor with the network device and inserts the network rights descriptor in each generated data packet. The network device is configured to discard the data packet if the network rights descriptor in the data packet does not match an authorized network rights descriptor and to process the data packet if the network rights descriptor in the data packet matches an authorized network rights descriptor.