Passive Information Manager for Network Service Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication methods for data-processing services face challenges in securely and reliably transferring user-identifying information and other data from client networks to service networks, leading to increased bandwidth usage, processing burdens, and limitations on data transmission due to encryption and re-transmission requirements.

Innovation Solution

The implementation of a Passive Information Manager (PIM) that creates a unique identifier (UID) for client devices, aggregates necessary information, and securely transmits it to a service network, allowing service devices to propagate this information using a peer-to-peer topology, ensuring minimal disruption and efficient data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is re-transmitted with each network communication in encrypted form, then security and confidentiality are improved, but bandwidth requirements increase and processing burden increases

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The client device performs preliminary action by transmitting user-identifying information and authentication data to the service device before actual service requests. This initial data transmission allows the service device to cache and store the information, eliminating the need for repeated encryption and decryption with each subsequent request, thereby reducing bandwidth consumption while maintaining security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data is re-transmitted with each network communication in encrypted form, then security and confidentiality are improved, but processing burden increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication and data exchange during an initial handshaking phase. Once authenticated, the service device stores user-identifying information locally, eliminating the need for repeated encryption and decryption operations during subsequent service requests, thereby significantly reducing processing burden on both client and service devices

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data is re-transmitted with each network communication, then service availability is improved through load balancing, but data transmission limits increase

Engineering Contradiction:
Improveservice availabilityVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The client device transmits necessary user-identifying information and authentication data during an initial preliminary phase to the service device. This initial transmission enables the service device to cache and store the information locally, allowing subsequent service requests to be handled without repeated data transmission, thereby reducing overall data transmission volume while maintaining service availability through load balancing across multiple service devices

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8200971B2Method for the provision of a network service
Publication Date: 2012.06.12 CISCO TECHNOLOGY INC
  • US8200971B2 patent drawing
  • US8200971B2 patent drawing
  • US8200971B2 patent drawing

AI summary

Methods and systems provide for sharing information between computer networks in which the information to be shared is required at one location (e.g. for the provision of a data-processing service) but is only available at a separate location. The information may be deliberately absent (e.g. for privacy reasons) or may be unavailable as an artifact of the computer network(s) involved. For the provision of a data-processing service, where several different devices on one network may service contiguous requests from a client device on another network according to a load-balancing strategy, data is propagated once only through the service network. Network communication software is subsequently amended to provide the minimal information necessary for a device on the service network to retrieve the information pertinent to the client device and necessary for its service. Therefore, a web-based single sign-on scheme can operate over HTTP to authorize data-processing services, such as web-filtering services.