PKI Session Authentication via In-Band Packet Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems lack efficient methods for secure, in-band authentication and policy enforcement within computer networks, particularly in environments with limited connectivity or restricted access, relying on external queries for security decisions.

Innovation Solution

Implementing public key infrastructure (PKI) based session authentication, where network devices verify identity context information and PKI information within packet metadata, enabling in-band cryptographic verification and policy application without external queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices use external queries for security decisions, then security verification can be performed, but network connectivity requirements increase and response time delays occur

Engineering Contradiction:
Improvesecurity verificationVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies preliminary action by embedding PKI authentication and identity context information in packet metadata before packets traverse the network. Routers can verify security decisions using pre-configured policy rules and embedded cryptographic signatures without needing external queries during packet forwarding, thus eliminating response time delays while maintaining security verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by using embedded PKI signatures and identity context information as intermediaries between the security verification system and packet forwarding process. These embedded credentials act as self-contained mediators that enable routers to make security decisions autonomously without external communication, resolving the contradiction between verification reliability and response speed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network devices rely on external queries for authentication, then security decisions can be made, but system complexity increases due to external communication requirements

Engineering Contradiction:
Improvesecurity decision makingVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication elements (PKI signatures, identity context information, policy rules) from external systems and embeds them directly into packet metadata and router configurations. This extraction eliminates the need for complex external communication infrastructure while maintaining security decision-making capability, thus reducing system complexity without compromising reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements self-service by enabling routers to autonomously verify packet authenticity using embedded PKI signatures and pre-configured policy rules. The system serves itself by making security decisions locally without external assistance, eliminating the complexity of external query mechanisms while maintaining reliable security enforcement

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If PKI authentication is implemented without external queries, then network connectivity requirements decrease, but cryptographic verification capability must be embedded in network devices

Engineering Contradiction:
Improveconnectivity independenceVSAvoidcryptographic verification capability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring routers with PKI verification capabilities and embedding cryptographic signatures in packet metadata before transmission. This preliminary setup enables connectivity-independent verification, allowing routers to autonomously authenticate packets using embedded credentials without requiring external communication infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements universality by designing a multi-functional embedded PKI verification system in routers that can handle multiple cryptographic operations (signature verification, identity validation, policy enforcement) using a single integrated mechanism. This universal approach enables connectivity independence while managing device complexity through consolidated cryptographic functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12494900B2Public key infrastructure based session authentication
Publication Date: 2025.12.09 JUNIPER NETWORKS INC
  • US12494900B2 patent drawing
  • US12494900B2 patent drawing
  • US12494900B2 patent drawing

AI summary

Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.