Network Traffic Manager for Automated Security Token Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In federated identity environments, manual processes for managing and revoking compromised security tokens are time-consuming, delaying the mitigation of security threats.

Innovation Solution

A network traffic manager system that monitors traffic between clients and web application servers, detects security violations, and modifies or revokes access tokens to restrict access to web applications, thereby enhancing the automated management of security tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used to identify and revoke compromised tokens, then administrators can manage security tokens, but the process is time-consuming and delays mitigation of security threats

Engineering Contradiction:
Improvesecurity threat mitigationVSAvoidtoken revocation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service functionality where the token management system automatically monitors network traffic, detects security violations, and revokes compromised tokens without requiring manual administrator intervention. The system serves itself by implementing automated threat detection and response mechanisms that continuously monitor and react to security events.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops by monitoring network traffic data, analyzing it for security violations, and automatically responding by revoking tokens when threats are detected. This closed-loop feedback mechanism ensures rapid response to security threats by constantly gathering information about system state and adjusting token validity based on detected violations.

Inventive Principle:
Principle #23Feedback

2Productivity

If automated monitoring and token modification is implemented, then security threat mitigation is improved, but system complexity increases

Engineering Contradiction:
Improvetoken revocation speedVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The token management system performs multiple functions within a single integrated platform: it issues tokens, monitors network traffic, detects security violations, modifies token claims, and revokes compromised tokens. This multi-functional approach consolidates what could be separate complex systems into one unified system that handles the entire token lifecycle and security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges token issuance, traffic monitoring, security analysis, and token revocation functions into a single integrated process. By combining these previously separate operations into one unified system, the patent reduces overall system complexity while maintaining automated security response capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10812266B1Methods for managing security tokens based on security violations and devices thereof
Publication Date: 2020.10.20 F5 NETWORKS INC
  • US10812266B1 patent drawing
  • US10812266B1 patent drawing
  • US10812266B1 patent drawing

AI summary

Methods, non-transitory computer readable media, and network traffic manager apparatus that assists managing security tokens based on security violations includes monitoring network traffic data between a client and a web application server. Next, the monitored network traffic data is determined for at least one security violation. One or more access tokens associated with the client is modified when the at least one security violation is detected in the monitored network traffic data. The client is restricted from accessing one or more web applications based on the modified one or more access tokens.