Secure Credentials for Distributed Exporter Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed virtual switch (DVS) networks, the scalability and security of network flow data export are compromised due to the distribution of exporters across multiple virtual machines, leading to vulnerabilities such as masquerade and replay attacks, and the inability to distinguish valid from fake senders, which affects billing and network security.

Innovation Solution

A system and method that utilize secure credentials, including IP addresses and digital signatures, to authenticate and authorize exporters within a secure domain, ensuring that only authorized entities can send data to a collector, thereby preventing spoofing and ensuring the integrity of network flow statistics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If exporters are distributed across multiple virtual machines in a DVS network, then network scalability and flexibility are improved, but security vulnerabilities increase due to inability to distinguish valid from fake senders

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces secure credentials as an intermediary mechanism between exporters and collectors. These credentials act as a mediator that verifies the authenticity of data sources, allowing the system to maintain both distributed architecture benefits and security requirements without compromising either aspect

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure credentials with digital signatures are implemented for all exporters, then security and authenticity are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring secure credentials with digital signatures in the exporter configurations before data export begins. This upfront setup eliminates the need for complex real-time verification mechanisms, reducing operational complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses digital signatures as cryptographic copies that verify authenticity without requiring the original exporter identity to be physically present or continuously verified. The signature acts as a replicable proof of authenticity that simplifies the verification process

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8584215B2System and method for securing distributed exporting models in a network environment
Publication Date: 2013.11.12 CISCO TECHNOLOGY INC
  • US8584215B2 patent drawing
  • US8584215B2 patent drawing
  • US8584215B2 patent drawing

AI summary

A method is provided in one example implementation and includes identifying a plurality of exporters that are authorized to communicate data to a collector on behalf of a secure domain; generating secure credentials for the secure domain; communicating the secure credentials to the collector; and authenticating the exporters using the secure credentials. In more particular implementations, the method can include receiving the secure credentials; receiving certain data that includes identifying information, which further includes an Internet protocol (IP) address of a source associated with the certain data; accepting the certain data if the secure credentials validate the identifying information; and rejecting the certain data if the secure credentials do not validate the identifying information.