Network Security Action Verification via Asset Credential Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing network security systems face challenges in verifying the authenticity of security actions before implementation, which can lead to improper actions crippling the network or introducing new security threats.

Innovation Solution

A method is introduced where the administration system identifies and verifies security actions by exchanging security parameters with computing assets, ensuring only approved actions are implemented, using credentials like usernames and passwords to authenticate and authorize security actions at the asset level, thereby preventing unauthorized implementations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If security actions are implemented without verification, then response speed to threats is improved, but network reliability deteriorates due to potential improper actions

Engineering Contradiction:
Improveresponse speedVSAvoidnetwork reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by verifying security actions through credential exchange before they are implemented on computing assets. The administration system exchanges credentials with the target asset, and only after successful verification is the security action executed. This ensures that while maintaining fast response speed, the network reliability is protected by preventing unauthorized or improper security actions from being executed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If centralized credential management is used, then ease of operation is improved, but security reliability worsens due to single point of failure

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies segmentation by distributing credential verification to individual computing assets rather than maintaining a centralized credential repository. Each computing asset stores its own credentials locally and performs self-verification when receiving security actions. This segmentation eliminates the single point of failure associated with centralized credential management while maintaining ease of operation through automated verification processes.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security actions are verified through credential exchange, then security reliability is improved, but device complexity increases due to verification protocols

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidverification protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling computing assets to perform their own credential verification autonomously without requiring complex centralized verification infrastructure. Each asset maintains its own credentials and independently verifies incoming security actions by exchanging credentials with the administration system. This self-service approach improves security reliability while minimizing device complexity by leveraging the existing capabilities of individual assets.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12074901B1Security action verification in a computing network
Publication Date: 2024.08.27 CISCO TECHNOLOGY INC
  • US12074901B1 patent drawing
  • US12074901B1 patent drawing
  • US12074901B1 patent drawing

AI summary

Systems, methods, and software described herein provide for validating security actions before they are implemented in a computing network. In one example, a computing network may include a plurality of computing assets that provide a variety of different operations. During the operations of the network, administration systems may generate and provide security actions to prevent or mitigate the effect of a security threat on the network. However, prior to implementing the security actions within the network, computing assets may exchange security parameters with the administration systems to verify that the security actions are authentic.