Network Routing via Authenticated Request Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional networks lack authentication mechanisms in their packet and session processing, leading to implicit trust that can result in rogue devices and applications going undetected, compromising network security.
Innovation Solution
The integration of Transport Access Control (TAC) and Statistical Object Identification (SOI) to authenticate network requests and establish explicit trust by using cryptographic hashes and analytics systems to verify identities, allowing only authenticated traffic to access network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional networks use implicit trust for packet and session processing, then network operation is simple and fast, but network security is compromised allowing rogue devices to go undetected
Solution Approach 1:
The patent applies preliminary action by authenticating network requests before routing them. The router verifies authentication information in packets before forwarding, ensuring security decisions are made in advance rather than reactively. This prevents rogue devices from accessing network resources while maintaining efficient packet forwarding for authenticated traffic.
Solution Approach 2:
The patent introduces an authentication information intermediary mechanism where routers verify authentication data embedded in packets. This intermediary layer of verification sits between the sending device and the network core, allowing security checks without fundamentally altering the underlying IP routing infrastructure. The authentication information acts as a mediator that enables secure routing decisions.
2Reliability
If networks authenticate all packets, then network security is improved, but processing time and computational overhead increase
Solution Approach 1:
The patent applies partial action by selectively authenticating only certain packets or traffic flows rather than all packets. The router can be configured to authenticate specific types of traffic or apply authentication only when suspicious patterns are detected. This partial authentication approach provides security for critical traffic while minimizing processing overhead for routine communications.
3Adaptability or versatility
If routers use traditional metric-based route selection, then routing is simple and efficient, but authenticated identity information is not considered in route selection
Solution Approach 1:
The patent merges traditional metric-based routing with authentication-based routing by combining multiple routing criteria into a unified route selection process. The router evaluates both conventional metrics (bandwidth, latency, cost) and authentication information (user identity, device trust level, policy compliance) together to determine the optimal route. This merging enables flexible, adaptive routing that considers both technical and security factors.
Solution Approach 2:
The patent introduces dynamics into route selection by making routing decisions adaptable to authentication results. Routes can be dynamically adjusted based on user identity, trust levels, and policy requirements. The routing table can contain multiple routes to the same destination with different authentication requirements, allowing the system to dynamically select appropriate routes based on real-time authentication outcomes.
Data Source
AI summary
The present invention enables the selection of network routes based on a combination of traditional route table entries, identity policy information, and trust level information determined dynamically for each network session. This enables a network operator to apply different policies to network entities presenting differing identity credentials. It also allows network operators to block access to networks and network resources when identity credentials are not provided or are unauthorized.


