Portable Network Device for Secure Component Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of new network components into data networks is complex due to the requirement for pre-existing authentication data, which cannot be accessed without initial network connectivity.

Innovation Solution

A portable network device with two interfaces connects to both access points and network components, authenticating itself using stored or generated authentication data to permit access to the network, allowing new components to obtain necessary credentials for direct connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication data are stored on new network components in advance, then access to the data network is enabled, but the complexity of integrating new network components increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A portable network device is introduced as an intermediary between the access-protected access point and the new network component. This intermediary device possesses authentication data and can authenticate itself at the access point, thereby mediating access for the new network component that lacks authentication data. This resolves the contradiction by enabling access without requiring pre-stored authentication data on the new component, thus maintaining reliability while reducing integration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The portable network device performs preliminary authentication actions by authenticating itself at the access point before the new network component can access the data network. This preliminary action establishes the authentication context and enables subsequent access for the new component, eliminating the need for the new component to have pre-stored authentication data and simplifying the integration process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If configuration of the data network is changed to allow new network component access, then access is enabled, but the complexity of network configuration increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The portable network device serves as a mediator that handles authentication requirements, eliminating the need to change data network configuration. By introducing this intermediary with pre-stored authentication data, the system enables new component access through device-level authentication rather than network-level configuration changes, thus maintaining access capability while reducing configuration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the portable network device permits access to the data network, then new network components can obtain authentication data, but security risks increase

Engineering Contradiction:
Improveintegration easeVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The portable network device implements local quality control by permitting access only to specific subnetworks within the data network where authentication data can be obtained, rather than allowing unrestricted access to the entire network. This localized access approach enables new components to obtain necessary credentials while limiting exposure to potential security risks in other parts of the network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The device applies partial action by providing limited, controlled access to only the portions of the data network necessary for obtaining authentication data, rather than full network access. This partial access strategy enables the essential function of credential retrieval while minimizing security risks associated with broader network exposure.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11165773B2Network device and method for accessing a data network from a network component
Publication Date: 2021.11.02 SIEMENS AG
  • US11165773B2 patent drawing
  • US11165773B2 patent drawing

AI summary

A network device, including two interfaces for connecting to an access-protected access point of a data network and to a network component which is to be allowed access to the data network via the access point is provided. The network device is designed to be authenticated at the access point using authentication data when the access point is connected and the network component is connected and to allow the connected network component to access the data network via the access point in the event of a successful authentication at least for network components which satisfy one or more specified criteria.