Flexible Source Identifier Validation via Dynamic Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network message matching systems rely on user-controlled source identifiers, which can be compromised by untrusted entities, leading to security vulnerabilities and inefficient resource utilization due to reliance on operating system trust.

Innovation Solution

Implementing a system that dynamically validates source identifiers using software-defined-matching and hardware-validated-matching schemes, independent of user-operated software, through a network interface card (NIC) to ensure trust in the source device without relying on the operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional user-controlled source identifiers are used for network message matching, then ease of operation is improved, but security reliability deteriorates due to compromise by untrusted entities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted intermediary component (security module or hypervisor) that mediates between untrusted user software and the network communication process. This intermediary validates source identifiers and enforces security policies without requiring changes to user applications, thus maintaining ease of operation while improving security reliability through independent verification of message sources

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-validated-matching schemes are implemented for source identifier validation, then security reliability is improved, but device complexity increases due to additional hardware validation mechanisms

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex hardware validation mechanisms with software-based or firmware-based validation schemes implemented in trusted execution environments. This substitution achieves equivalent security reliability through logical validation and cryptographic verification while avoiding the increased device complexity associated with dedicated hardware validation circuits

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements a universal validation mechanism that can operate in multiple modes (hardware-validated-matching, software-defined-matching, or hybrid approaches) depending on system capabilities and security requirements. This multi-functionality allows the same system to achieve high security reliability across different platforms without requiring specialized hardware for each validation scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250112859A1Flexible validation of source identifiers
Publication Date: 2025.04.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250112859A1 patent drawing
  • US20250112859A1 patent drawing
  • US20250112859A1 patent drawing

AI summary

Systems and methods are provided for validating an identifier using a dynamic matching scheme, including software-defined-matching or hardware-validated-matching. Software-defined-matching may determine whether two identifiers are logically the same when they are both generated by a software application and match each other, and hardware-validated-matching may determine whether the identifier provided by a message stamping process generated by a hardware component of the device matches a second identifier. The flexible validation process can allow the origin of the device to be trusted when the device is sending communications in the network, while detaching the trust from the user that is operating the trusted device or installing software (e.g., an operating system) on the device for temporary use. By disassociating the trust and independently verifying the device separate from the user operating the device, the communications sent and received by the system can be further trusted or distrusted accordingly.