Relay Device Authentication for Secure Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet relay devices lack authentication processing between relay devices, leading to security gaps and increased costs in large networks due to the need for extensive updates when new devices are added.

Innovation Solution

A relay device with input/output ports connected to multiple devices, including other relay devices, featuring an authentication information storage unit, authentication processing unit, and relay processing unit that performs authentication and manages packet transfer based on stored authentication information, ensuring secure communication between relay devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication processing is not performed between relay devices, then device complexity is reduced and ease of operation is improved, but security of the network deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication function is segmented and integrated into individual relay devices, allowing each relay device to independently perform authentication with its neighbors. This distributes the security function across multiple nodes rather than requiring a centralized authentication system, thereby improving network security without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Relay devices perform authentication autonomously using pre-stored authentication information, without requiring external authentication servers or manual configuration. Each relay device serves its own authentication needs by comparing received authentication packets against stored credentials, enabling self-contained security operations that improve reliability while maintaining operational simplicity.

Inventive Principle:
Principle #25Self-service

2Reliability

If white list authentication is implemented across the entire network, then network security is improved, but device complexity increases and ease of operation deteriorates due to required updates

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork maintenance ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is divided into independent segments at each relay device, with each device maintaining its own authentication information locally. This eliminates the need for centralized white list management and network-wide updates when devices are added or removed, as each relay device independently validates authentication packets from its direct neighbors using pre-configured credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication approach changes from dynamic centralized white list management to static pre-configured authentication information at each relay device. By changing the authentication parameter from a centrally-controlled dynamic list to distributed static credentials, the system achieves improved security without the operational burden of network-wide updates.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11870777B2Relay device and communication system
Publication Date: 2024.01.09 MITSUBISHI ELECTRIC CORP
  • US11870777B2 patent drawing
  • US11870777B2 patent drawing
  • US11870777B2 patent drawing

AI summary

A relay device includes a plurality of input/output ports (111); an authentication information storage unit (114) to store authentication information used for performing authentication of a target relay device which is a relay device to be authenticated; an authentication processing unit (113) to acquire a target authentication packet which is an authentication packet used for authentication of the target relay device via a target input/output port (111) which is an input/output port connected to the target relay device in the plurality of input/output ports and to authenticate the target relay device by referring to the authentication information, and a relay processing unit (112) to cause a transfer input/output port which is an input/output port (111) to which a transfer destination of the transfer packet is connected, and to discard the transfer packet when the authentication of the target relay device is failed.