Network Security via Device Identifier Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems fail to effectively identify and prevent malicious network communications, as hackers and unauthorized users exploit vulnerabilities in network addresses and device identifiers to infiltrate corporate and government networks, leading to data breaches and undesirable actions.

Innovation Solution

The implementation of a system that evaluates network addresses and device identifiers against a list of trusted entities, using a white list to validate communications and apply varying levels of access based on trust levels, including the use of non-modifiable device identifiers and geographic location verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security systems are used to monitor and detect malicious communications, then network traffic can be analyzed, but unauthorized access and data breaches cannot be effectively prevented because hackers exploit vulnerabilities in network addresses and device identifiers

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidunauthorized access and data breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation by maintaining a white list of trusted network addresses and device identifiers before allowing communications. By pre-establishing trusted entity records and checking incoming communications against this white list, the system prevents malicious communications from establishing connections, rather than merely detecting them after infiltration attempts occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism that sits between network communications and the target system. This intermediary layer evaluates incoming communications by comparing network addresses and device identifiers against the white list of trusted entities, acting as a mediator that allows legitimate communications while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network addresses and device identifiers are used to identify communications, then communication tracking is enabled, but hackers can exploit vulnerabilities in these identifiers to infiltrate networks

Engineering Contradiction:
Improvecommunication identification accuracyVSAvoidvulnerability exploitation detection
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system pre-establishes a white list containing validated network addresses and device identifiers of trusted entities before communications occur. By performing this validation preparation in advance, the system creates a reference framework that enables accurate identification of legitimate communications while making it difficult for hackers to exploit identifier vulnerabilities, as any deviation from the pre-validated list is automatically detected.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a white list of trusted entities is implemented to validate communications, then unauthorized access is prevented, but system complexity increases due to multiple validation layers

Engineering Contradiction:
Improveaccess control securityVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation system is segmented into distinct functional components: a white list storage module that maintains trusted entity records, an evaluation module that performs the actual validation, and a communication control module that enforces access decisions. This segmentation allows each component to perform its specific function efficiently, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The evaluation module serves multiple functions: it validates network addresses, verifies device identifiers, checks communication patterns, and makes access control decisions. By consolidating these multiple validation functions into a single universal module, the system reduces complexity compared to having separate dedicated systems for each validation task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10382436B2Network security based on device identifiers and network addresses
Publication Date: 2019.08.13 CHIEN DANIEL
  • US10382436B2 patent drawing
  • US10382436B2 patent drawing
  • US10382436B2 patent drawing

AI summary

Techniques for network security are disclosed. In some implementations, an evaluation module determines whether a network communication from a computing device is allowable. The allowability of the communication is determined based on (1) whether the computing device is using an authorized source network address, and (2) whether a non-modifiable identifier of the computing device is authorized. The non-modifiable identifier is a fixed hardware identifier of the computing device, such as an identifier of a CPU, network interface card, storage device, or the like.