PKI Session Authentication via In-Band Packet Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network systems lack efficient methods for secure, in-band authentication and policy enforcement within computer networks, particularly in environments with limited connectivity or restricted access, relying on external queries for security decisions.
Innovation Solution
Implementing public key infrastructure (PKI) based session authentication, where network devices verify identity context information and PKI information within packet metadata, enabling in-band cryptographic verification and policy application without external queries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices use external queries for security decisions, then security verification can be performed, but network connectivity requirements increase and response time delays occur
Solution Approach 1:
The patent applies preliminary action by embedding PKI authentication and identity context information in packet metadata before packets traverse the network. Routers can verify security decisions using pre-configured policy rules and embedded cryptographic signatures without needing external queries during packet forwarding, thus eliminating response time delays while maintaining security verification
Solution Approach 2:
The patent introduces an intermediary mechanism by using embedded PKI signatures and identity context information as intermediaries between the security verification system and packet forwarding process. These embedded credentials act as self-contained mediators that enable routers to make security decisions autonomously without external communication, resolving the contradiction between verification reliability and response speed
2Reliability
If network devices rely on external queries for authentication, then security decisions can be made, but system complexity increases due to external communication requirements
Solution Approach 1:
The patent extracts the essential authentication elements (PKI signatures, identity context information, policy rules) from external systems and embeds them directly into packet metadata and router configurations. This extraction eliminates the need for complex external communication infrastructure while maintaining security decision-making capability, thus reducing system complexity without compromising reliability
Solution Approach 2:
The patent implements self-service by enabling routers to autonomously verify packet authenticity using embedded PKI signatures and pre-configured policy rules. The system serves itself by making security decisions locally without external assistance, eliminating the complexity of external query mechanisms while maintaining reliable security enforcement
3Adaptability or versatility
If PKI authentication is implemented without external queries, then network connectivity requirements decrease, but cryptographic verification capability must be embedded in network devices
Solution Approach 1:
The patent applies preliminary action by pre-configuring routers with PKI verification capabilities and embedding cryptographic signatures in packet metadata before transmission. This preliminary setup enables connectivity-independent verification, allowing routers to autonomously authenticate packets using embedded credentials without requiring external communication infrastructure
Solution Approach 2:
The patent implements universality by designing a multi-functional embedded PKI verification system in routers that can handle multiple cryptographic operations (signature verification, identity validation, policy enforcement) using a single integrated mechanism. This universal approach enables connectivity independence while managing device complexity through consolidated cryptographic functionality
Data Source
AI summary
Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.


