Network User Identification via Unique Packet Embedding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security models are inadequate for identifying and authenticating users at the network layer, leading to vulnerabilities that allow anonymous attackers to breach high-profile internet services, causing significant damage and compromising user credentials.

Innovation Solution

A method that involves including unique identification information in network layer packets, independent of network addresses, allowing for secure verification and authentication of user entities at the network layer, enabling secure access control and reducing the need for traditional password-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IP address-based security models are used, then network communication is simple and compatible, but user identity verification is insufficient and security is compromised

Engineering Contradiction:
Improveuser identity verificationVSAvoidnetwork security model
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds a user identity module within the network layer packet structure, nesting the unique identification information inside the existing IP packet framework. This allows user identity verification to be integrated into the fundamental network communication protocol without requiring separate authentication systems, thereby improving reliability while managing complexity through hierarchical integration

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent transitions from two-dimensional IP address-based identification to three-dimensional identification by adding the user identity dimension. Network packets now carry both source/destination IP addresses and unique user identification information, enabling verification across multiple dimensions simultaneously. This resolves the contradiction by providing robust identity verification without completely redesigning the network model

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If application-specific user identity authentication is implemented, then user identity can be verified, but multiple credentials must be managed and security breaches can occur

Engineering Contradiction:
Improveuser authenticationVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal user identity system that operates across all applications and network services. By implementing user identification at the network layer rather than the application layer, a single user identity can authenticate across multiple applications simultaneously. This eliminates the need for users to manage separate credentials for each service, improving ease of operation while maintaining strong authentication through the unified network-level verification mechanism

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If network layer user identification is implemented, then security is enhanced and access control is improved, but network packet structure becomes more complex

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork packet structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identification function into separate components: IP address handling remains at the traditional network layer while user identity information is placed in dedicated fields within the packet structure. This segmentation allows security enhancement through user identification without fundamentally complicating the overall packet structure, as each component maintains its own simplified processing rules

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9699158B2Network user identification and authentication
Publication Date: 2017.07.04 GOODWIN RUSSELL S
  • US9699158B2 patent drawing
  • US9699158B2 patent drawing
  • US9699158B2 patent drawing

AI summary

A method of identifying and authenticating a network user includes receiving a first network layer packet from a first user entity. The first network layer packet may include first unique identification information unique to the first user entity and independent of a first network address associated with the first network layer packet. The method further includes verifying, at a network layer of a network, that the first network layer packet is from the first user entity based on the first unique identification information.