Power Interface Endpoint Authentication via Physical Challenge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to authenticate endpoint devices in computer networks to ensure that the device connected to a power interface is the expected device, as endpoint devices can be easily added or removed, and existing methods lack effective verification mechanisms.

Innovation Solution

A physical power challenge is used to authenticate endpoint devices by requesting them to perform a specific power signature, with proof of work information collected by the power interface and sensor devices, which is then evaluated to confirm the device's identity and trigger alerts if authentication fails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If endpoint devices are easily added or removed from the network by plugging them in, then network flexibility and ease of operation are improved, but network security and authentication reliability deteriorate because unauthorized devices can be easily connected

Engineering Contradiction:
Improveease of device connectionVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication actions before allowing network access. A power challenge is issued to the endpoint device before it is fully authenticated, requiring the device to demonstrate specific power consumption characteristics that verify its identity. This preliminary verification ensures that only authorized devices can be added to the network, resolving the security issue while maintaining ease of connection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system uses feedback from power consumption measurements to verify device identity. The power interface monitors the endpoint device's power consumption pattern in response to a challenge, and this feedback is used to determine whether the device is authenticated. This feedback mechanism enables reliable authentication without complicating the connection process.

Inventive Principle:
Principle #23Feedback

2Device complexity

If traditional authentication methods are used without physical verification, then authentication process simplicity is maintained, but the ability to verify actual device presence and identity deteriorates

Engineering Contradiction:
Improveauthentication process complexityVSAvoiddevice identity verification precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The power interface acts as an intermediary between the network and the endpoint device for authentication purposes. Instead of relying solely on network-layer authentication, the power interface mediates the verification process by measuring power consumption characteristics. This intermediary approach adds precise physical verification without significantly increasing the complexity of the authentication process from the user perspective.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces traditional network-based authentication mechanisms with a physical power-based verification system. Instead of relying on software-based credentials that can be spoofed, the system uses physical power consumption measurements to verify device identity. This substitution of mechanical/physical verification for software-based authentication improves measurement precision while maintaining process simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10235516B2Method for authenticating a networked endpoint using a physical (power) challenge
Publication Date: 2019.03.19 CISCO TECHNOLOGY INC
  • US10235516B2 patent drawing
  • US10235516B2 patent drawing
  • US10235516B2 patent drawing

AI summary

Various systems and methods for using power challenges to authenticate network devices are disclosed herein. For example, one method involves initiating a power challenge to authenticate an endpoint device, which involves, at least in part, requesting the endpoint device to perform a specific power signature; receiving data indicating whether the endpoint device performed the requested power signature within a given time interval, wherein the data can be received from, e.g., a power interface or other device capable of observing the endpoint device; processing the received data to determine if the endpoint device correctly performed the requested power signature; and if the endpoint correctly performed the power signature, authenticating the endpoint.