Redundant System Process Authentication via Node Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In redundant systems, existing methods for authenticating processes to prevent unauthorized execution are costly and vulnerable to system compromise if root privileges are stolen, as they require additional storage media, which increases costs and reduces security.

Innovation Solution

A method and apparatus that distribute and store unique process information across neighboring nodes in a redundant system, allowing execution nodes to authenticate processes by comparing local data with adjacent data from neighboring nodes, thereby reducing the need for additional authentication storage and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique information about each process is stored in a single system, then process authentication can be performed, but if system root privileges are stolen, the system becomes incapacitated and additional storage media are required

Engineering Contradiction:
Improvesystem securityVSAvoidstorage medium configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication data storage across multiple nodes in a redundant system. Each node stores authentication information for processes that may execute on it, rather than centralizing all authentication data in a single system. This segmentation ensures that if one node is compromised, other nodes retain their authentication capabilities and can continue to secure process execution.

Inventive Principle:
Principle #1Segmentation

2Reliability

If additional storage media are added to prevent unauthorized process execution, then security is improved, but system costs increase

Engineering Contradiction:
Improveprocess authentication securityVSAvoidstorage medium quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the existing redundant system nodes serve a dual function: they continue to provide their primary computational services while also serving as storage media for process authentication data. This eliminates the need for dedicated additional storage media, as the same hardware infrastructure is utilized for both computation and authentication data storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If unique process information is distributed across neighboring nodes, then authentication security is improved, but data distribution complexity increases

Engineering Contradiction:
Improveauthentication data securityVSAvoiddata distribution mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where each node automatically determines which authentication data to store based on the processes that may execute on it. When a process is transferred or created, the source node automatically provides the necessary authentication information to the destination node without requiring complex centralized management or manual configuration of data distribution.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10205714B2Apparatus and method for process authentication in redundant system
Publication Date: 2019.02.12 ELECTRONICS & TELECOMM RES INST
  • US10205714B2 patent drawing
  • US10205714B2 patent drawing
  • US10205714B2 patent drawing

AI summary

Disclosed herein is an apparatus and method for authenticating a process. According to the method for authenticating a process, a neighboring node transmits adjacent authentication data to an execution node, the execution node authenticates a process to be executed by comparing local authentication data with the adjacent authentication data, and the execution node executes the corresponding process.