Signed Send Token Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protected networks face challenges in securely allowing access to untrusted computing devices while preventing unauthorized access and maintaining scalability.

Innovation Solution

The distribution and use of signed send tokens, which include transmission information and encryption keys, are used to authenticate and encrypt data packets, allowing authorized access while preventing unauthorized access by untrusted devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If signed send tokens are distributed to untrusted computing devices, then network access is enabled for these devices, but security risk increases due to potential unauthorized access

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network access control by distributing individual signed send tokens to specific untrusted computing devices. Each token represents a discrete access authorization that can be independently managed, verified, and revoked. This segmentation allows the network to grant access to multiple untrusted devices without compromising overall security, as each device operates with its own isolated authorization credential.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The signed send token acts as an intermediary credential between untrusted computing devices and the protected network. The token contains cryptographic signatures that mediate the trust relationship, allowing the network to verify device authorization without requiring direct trust in the untrusted devices themselves. This intermediary mechanism resolves the security contradiction by introducing a verifiable trust layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional access control methods are used for untrusted devices, then security is maintained, but network scalability is limited due to resource constraints

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent uses cryptographic copying where the signed send token can be replicated and distributed to multiple untrusted devices without requiring proportional increases in network security resources. The digital signature on each token provides verifiable authorization, allowing the network to scale access control to numerous devices while maintaining security through immutable cryptographic verification rather than resource-intensive per-device monitoring.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the parameter of access control from resource-intensive continuous monitoring to lightweight cryptographic verification. By transforming the security mechanism into a parameter-based system where tokens contain embedded authorization parameters (signatures, expiration times, device identifiers), the network can handle scalable numbers of untrusted devices with constant security resource requirements.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access control mechanisms are implemented for each untrusted device, then unauthorized access is prevented, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple access control functions into a single signed send token structure. The token combines device identification, authorization signatures, expiration timing, and network access parameters into one integrated credential. This merging reduces system complexity by eliminating the need for separate management of multiple discrete access control mechanisms while maintaining comprehensive access control capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The signed send token serves multiple functions simultaneously: it authenticates the untrusted device, authorizes network access, establishes security parameters, and provides timing constraints. This multi-functionality reduces system complexity by replacing what would otherwise require separate systems for authentication, authorization, accounting, and access control with a single universal token mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10021077B1System and method for distributing and using signed send tokens
Publication Date: 2018.07.10 GOOGLE LLC
  • US10021077B1 patent drawing
  • US10021077B1 patent drawing
  • US10021077B1 patent drawing

AI summary

The disclosed system allows a user to have access to a protected network through the distribution of signed send tokens. In particular, a device associated with the protected network, such as a network interface card, may generate and issue send tokens to various third-parties who seek access to the network. A send token may be a block of data that contains transmission information regarding the operations that are allowed to be performed by the network user. For example, the send token may identify the portions of the network to which the user's data packets are allowed to be sent, as well as the permitted content of the user's data packets.