Passive Information Manager for Network Service Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication methods for data-processing services face challenges in securely and reliably transferring user-identifying information and other data from client networks to service networks, leading to increased bandwidth usage, processing burdens, and limitations on data transmission due to encryption and re-transmission requirements.
Innovation Solution
The implementation of a Passive Information Manager (PIM) that creates a unique identifier (UID) for client devices, aggregates necessary information, and securely transmits it to a service network, allowing service devices to propagate this information using a peer-to-peer topology, ensuring minimal disruption and efficient data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is re-transmitted with each network communication in encrypted form, then security and confidentiality are improved, but bandwidth requirements increase and processing burden increases
Solution Approach 1:
The client device performs preliminary action by transmitting user-identifying information and authentication data to the service device before actual service requests. This initial data transmission allows the service device to cache and store the information, eliminating the need for repeated encryption and decryption with each subsequent request, thereby reducing bandwidth consumption while maintaining security
2Reliability
If data is re-transmitted with each network communication in encrypted form, then security and confidentiality are improved, but processing burden increases
Solution Approach 1:
The system performs preliminary authentication and data exchange during an initial handshaking phase. Once authenticated, the service device stores user-identifying information locally, eliminating the need for repeated encryption and decryption operations during subsequent service requests, thereby significantly reducing processing burden on both client and service devices
3Reliability
If data is re-transmitted with each network communication, then service availability is improved through load balancing, but data transmission limits increase
Solution Approach 1:
The client device transmits necessary user-identifying information and authentication data during an initial preliminary phase to the service device. This initial transmission enables the service device to cache and store the information locally, allowing subsequent service requests to be handled without repeated data transmission, thereby reducing overall data transmission volume while maintaining service availability through load balancing across multiple service devices
Data Source
AI summary
Methods and systems provide for sharing information between computer networks in which the information to be shared is required at one location (e.g. for the provision of a data-processing service) but is only available at a separate location. The information may be deliberately absent (e.g. for privacy reasons) or may be unavailable as an artifact of the computer network(s) involved. For the provision of a data-processing service, where several different devices on one network may service contiguous requests from a client device on another network according to a load-balancing strategy, data is propagated once only through the service network. Network communication software is subsequently amended to provide the minimal information necessary for a device on the service network to retrieve the information pertinent to the client device and necessary for its service. Therefore, a web-based single sign-on scheme can operate over HTTP to authorize data-processing services, such as web-filtering services.


