Network Routing via Authenticated Request Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networks lack authentication mechanisms in their packet and session processing, leading to implicit trust that can result in rogue devices and applications going undetected, compromising network security.

Innovation Solution

The integration of Transport Access Control (TAC) and Statistical Object Identification (SOI) to authenticate network requests and establish explicit trust by using cryptographic hashes and analytics systems to verify identities, allowing only authenticated traffic to access network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional networks use implicit trust for packet and session processing, then network operation is simple and fast, but network security is compromised allowing rogue devices to go undetected

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by authenticating network requests before routing them. The router verifies authentication information in packets before forwarding, ensuring security decisions are made in advance rather than reactively. This prevents rogue devices from accessing network resources while maintaining efficient packet forwarding for authenticated traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication information intermediary mechanism where routers verify authentication data embedded in packets. This intermediary layer of verification sits between the sending device and the network core, allowing security checks without fundamentally altering the underlying IP routing infrastructure. The authentication information acts as a mediator that enables secure routing decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If networks authenticate all packets, then network security is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively authenticating only certain packets or traffic flows rather than all packets. The router can be configured to authenticate specific types of traffic or apply authentication only when suspicious patterns are detected. This partial authentication approach provides security for critical traffic while minimizing processing overhead for routine communications.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If routers use traditional metric-based route selection, then routing is simple and efficient, but authenticated identity information is not considered in route selection

Engineering Contradiction:
Improveroute selection flexibilityVSAvoidrouting decision complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges traditional metric-based routing with authentication-based routing by combining multiple routing criteria into a unified route selection process. The router evaluates both conventional metrics (bandwidth, latency, cost) and authentication information (user identity, device trust level, policy compliance) together to determine the optimal route. This merging enables flexible, adaptive routing that considers both technical and security factors.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces dynamics into route selection by making routing decisions adaptable to authentication results. Routes can be dynamically adjusted based on user identity, trust levels, and policy requirements. The routing table can contain multiple routes to the same destination with different authentication requirements, allowing the system to dynamically select appropriate routes based on real-time authentication outcomes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11265249B2Method for using authenticated requests to select network routes
Publication Date: 2022.03.01 INVISINET TECHNOLOGIES LLC
  • US11265249B2 patent drawing
  • US11265249B2 patent drawing
  • US11265249B2 patent drawing

AI summary

The present invention enables the selection of network routes based on a combination of traditional route table entries, identity policy information, and trust level information determined dynamically for each network session. This enables a network operator to apply different policies to network entities presenting differing identity credentials. It also allows network operators to block access to networks and network resources when identity credentials are not provided or are unauthorized.