Network Authentication via Statistical Object Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies face challenges in efficiently authenticating network traffic in arbitrary topologies, particularly due to resource-intensive endpoint solutions and network appliance bottlenecks, which can impact performance and are costly to implement and maintain.
Innovation Solution
An apparatus using a network endpoint device with a hardware processor and authentication device that performs statistical object identification, offloading authentication processes to a remote device, allowing for secure authentication without requiring the appliance to be in the network data path, thereby reducing resource consumption and improving enforcement of network policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint security technologies are deployed directly on each computer, then security authentication is performed, but endpoint resources (CPU, memory, network bandwidth) are substantially consumed
Solution Approach 1:
The patent extracts the authentication function from the endpoint device and places it in a separate network appliance. The endpoint device only needs to establish TCP connections, while the network appliance performs statistical object identification and authentication, thereby removing the resource-intensive authentication burden from endpoint resources.
Solution Approach 2:
The network appliance acts as an intermediary between endpoint devices and the network. It receives TCP connections from endpoints, performs authentication using statistical object identification, and then allows authenticated traffic to pass through. This mediator approach enables authentication without consuming endpoint resources.
2Device complexity
If network security appliances are deployed to provide security for multiple computers, then a single device provides security, but the appliance becomes a bottleneck and impacts traffic performance
Solution Approach 1:
The network appliance performs partial authentication - only analyzing statistical patterns from TCP handshakes and connection metadata rather than deep packet inspection of all traffic. This partial action approach provides sufficient security authentication while minimizing impact on traffic flow performance.
Solution Approach 2:
The system changes the parameter of authentication from deep packet inspection to statistical object identification based on TCP connection metadata. This parameter change enables faster authentication that doesn't bottleneck traffic flow while still providing security.
3Reliability
If network security appliances are deployed, then security functions are provided, but the appliance requires specific network topology where traffic must pass through it, which is often unachievable in arbitrary topologies
Solution Approach 1:
The network appliance is designed to work with multiple network topologies and deployment scenarios. It can be deployed in various positions in the network and adapt to different traffic patterns, making it universally applicable rather than requiring specific topology arrangements.
Solution Approach 2:
The endpoint devices themselves participate in the authentication process by establishing TCP connections that include statistical objects. The system uses the existing TCP handshake process to convey authentication information, eliminating the need for separate authentication traffic paths or specific topology requirements.
4Reliability
If cryptographic keys are widely distributed to every participating entity, then authentication is enabled, but the protection of those keys becomes more difficult to maintain
Solution Approach 1:
The patent extracts cryptographic key usage from the endpoint devices and centralizes it in the network appliance. Endpoint devices do not need to store or manage cryptographic keys - the network appliance performs statistical object identification without requiring key distribution to endpoints, thereby eliminating key protection complexity.
Data Source
AI summary
Apparatus to enforce network policy based on identity authentication at a network endpoint device by offloading the authentication to a network attached authentication devices is disclosed. The authentication device may use Statistical Object Identification to perform the authentication. The present disclosure greatly reduces the resources needed by the network endpoint device to perform the authentication and eliminates the topological restrictions found in traditional network appliance based approaches.


