Dynamic Security Server Discovery via Authentication Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication and authorization processes require manual configuration of security server contact information, which is time-consuming and error-prone, especially in larger networks, and existing dynamic discovery mechanisms are ineffective when IP connectivity is dependent on prior authentication and authorization.

Innovation Solution

Security server contact information is dynamically propagated throughout the network by secured devices acting as proxies during authentication and authorization exchanges, eliminating the need for manual configuration and enabling dynamic discovery even without initial IP connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security server contact information is used, then network security can be enforced, but the process becomes time-consuming and error-prone as networks scale

Engineering Contradiction:
Improvenetwork security enforcementVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling network devices to automatically discover and configure security server contact information through security exchange messages without manual intervention. Devices autonomously obtain necessary configuration data during authentication processes, eliminating the need for administrators to manually configure each device while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by embedding security server contact information within security exchange messages that are sent before actual security enforcement begins. This allows devices to pre-configure necessary contact information during initial authentication handshakes, so that when security enforcement starts, all devices are already properly configured without requiring additional manual setup time.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If dynamic discovery mechanisms like DNS SRV Record are used, then manual configuration is eliminated, but the mechanism fails when IP connectivity depends on prior authentication

Engineering Contradiction:
Improvedynamic discoveryVSAvoiddiscovery effectiveness
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent inverts the traditional discovery approach by not having devices search for servers, but rather having servers proactively provide their contact information to devices during security exchanges. This reversal eliminates the need for devices to establish IP connectivity before discovery, as the server contact information is delivered directly during the authentication process itself, solving the chicken-and-egg problem of connectivity dependency.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent uses security exchange messages as an intermediary carrier to transmit contact information. These messages serve as a trusted mediation channel between servers and devices, allowing contact information to be delivered reliably even when traditional IP connectivity pathways are not yet established. The security exchange protocol itself becomes the vehicle for information delivery, bypassing the need for separate discovery infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If security server contact information is distributed dynamically during security exchanges, then automation is achieved, but additional network communication overhead is introduced

Engineering Contradiction:
Improvecontact information distributionVSAvoidcommunication protocol complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent merges the contact information distribution function with the existing security exchange protocol. By embedding contact information within already-necessary authentication and authorization messages, the system combines multiple functions into a single communication flow. This eliminates the need for separate discovery protocols or additional message exchanges, as the contact information is piggybacked on messages that must be exchanged anyway for security purposes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes security exchange messages multi-functional by using them both for their primary security authentication purpose and for the secondary purpose of distributing contact information. This universal usage means that a single message type serves multiple functions, reducing overall system complexity rather than increasing it, as no dedicated contact information transmission mechanism needs to be created.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8037514B2Method and apparatus for securely disseminating security server contact information in a network
Publication Date: 2011.10.11 CISCO TECHNOLOGY INC
  • US8037514B2 patent drawing
  • US8037514B2 patent drawing
  • US8037514B2 patent drawing

AI summary

Various systems and method are disclosed for disseminating security server contact information in a network. For example, one method (e.g., performed by a security server) involves determining that a network device is a secure network device, in response to participating in a security exchange with the network device; and then sending a server list to the network device. The server list includes the network address of at least one security server. Another method (e.g., performed by a network device) involves initiating an authentication exchange; receiving a server list, which includes the network address of a security server, as part of the authentication exchange; and communicating with the security server by sending a packet to the network address included in the server list.