Port Operation Device Pre-Authentication Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network vulnerabilities make communication services susceptible to unauthorized access and cybercrimes, as malicious entities can exploit open ports to gain access to servers, leading to potential data compromise and disruption.

Innovation Solution

Implementing a port operation device that initially operates in a deactivated mode, pre-authenticates user devices based on received information, and activates the port only for authenticated users, thereby preventing unauthorized access by discarding service requests from unverified entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the port is kept in an activated mode to allow user devices to obtain communication services, then the ease of operation is improved, but the network security deteriorates as malicious entities can exploit open ports for unauthorized access

Engineering Contradiction:
Improveease of obtaining communication servicesVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs pre-authentication of user devices before activating the port. The port operation device receives a pre-authentication request from a user device, verifies credentials against an authentication database, and only then activates the port. This preliminary authentication action ensures that only authorized devices can access communication services, resolving the contradiction between ease of operation and network security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the port is kept in a deactivated mode to prevent unauthorized access, then the network security is improved, but the ease of operation deteriorates as legitimate users cannot access communication services

Engineering Contradiction:
Improvenetwork securityVSAvoidease of obtaining communication services
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The port operation device dynamically changes the port state from deactivated to activated based on authentication results. The port is maintained in a deactivated state by default for security, but automatically transitions to an activated state when a legitimate user device presents valid credentials. This dynamic adaptation resolves the contradiction by making the system secure by default while remaining accessible to authorized users.

Inventive Principle:
Principle #15Dynamics

3Productivity

If the port remains activated for authenticated users, then the productivity is improved by allowing continuous communication services, but the loss of energy increases due to maintaining open connections

Engineering Contradiction:
Improvecommunication service availabilityVSAvoidserver resource utilization
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The port operation device implements periodic re-authentication or connection validation for authenticated user devices. Instead of maintaining permanently open ports, the system periodically verifies the continued legitimacy of active connections and deactivates ports that exceed session timeouts or fail re-authentication. This periodic action maintains productivity for legitimate users while reducing energy loss by closing idle or suspicious connections.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11916894B2Protecting against network vulnerabilities
Publication Date: 2024.02.27 UAB 360 IT
  • US11916894B2 patent drawing
  • US11916894B2 patent drawing
  • US11916894B2 patent drawing

AI summary

A method including pre-authenticating, by an infrastructure device, a user device for obtaining communication services from a server, the pre-authenticating including determining a given duration of time and a communication parameter associated with a pre-authentication request received from the user device; and operating, by the infrastructure device, a port associated with the server in an activated mode for the given duration of time to enable the user device to transmit an authentication request indicating the communication parameter prior to an expiration of the given duration of time. Various other aspects are contemplated.