Network Authentication via Statistical Object Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies face challenges in efficiently authenticating network traffic in arbitrary topologies, particularly due to resource-intensive endpoint solutions and network appliance bottlenecks, which can impact performance and are costly to implement and maintain.

Innovation Solution

An apparatus using a network endpoint device with a hardware processor and authentication device that performs statistical object identification, offloading authentication processes to a remote device, allowing for secure authentication without requiring the appliance to be in the network data path, thereby reducing resource consumption and improving enforcement of network policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint security technologies are deployed directly on each computer, then security authentication is performed, but endpoint resources (CPU, memory, network bandwidth) are substantially consumed

Engineering Contradiction:
Improvesecurity authenticationVSAvoidendpoint resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication function from the endpoint device and places it in a separate network appliance. The endpoint device only needs to establish TCP connections, while the network appliance performs statistical object identification and authentication, thereby removing the resource-intensive authentication burden from endpoint resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network appliance acts as an intermediary between endpoint devices and the network. It receives TCP connections from endpoints, performs authentication using statistical object identification, and then allows authenticated traffic to pass through. This mediator approach enables authentication without consuming endpoint resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If network security appliances are deployed to provide security for multiple computers, then a single device provides security, but the appliance becomes a bottleneck and impacts traffic performance

Engineering Contradiction:
Improvesingle security deviceVSAvoidtraffic flow performance
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The network appliance performs partial authentication - only analyzing statistical patterns from TCP handshakes and connection metadata rather than deep packet inspection of all traffic. This partial action approach provides sufficient security authentication while minimizing impact on traffic flow performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of authentication from deep packet inspection to statistical object identification based on TCP connection metadata. This parameter change enables faster authentication that doesn't bottleneck traffic flow while still providing security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If network security appliances are deployed, then security functions are provided, but the appliance requires specific network topology where traffic must pass through it, which is often unachievable in arbitrary topologies

Engineering Contradiction:
Improvesecurity functionVSAvoidnetwork topology flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network appliance is designed to work with multiple network topologies and deployment scenarios. It can be deployed in various positions in the network and adapt to different traffic patterns, making it universally applicable rather than requiring specific topology arrangements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The endpoint devices themselves participate in the authentication process by establishing TCP connections that include statistical objects. The system uses the existing TCP handshake process to convey authentication information, eliminating the need for separate authentication traffic paths or specific topology requirements.

Inventive Principle:
Principle #25Self-service

4Reliability

If cryptographic keys are widely distributed to every participating entity, then authentication is enabled, but the protection of those keys becomes more difficult to maintain

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey distribution and protection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts cryptographic key usage from the endpoint devices and centralizes it in the network appliance. Endpoint devices do not need to store or manage cryptographic keys - the network appliance performs statistical object identification without requiring key distribution to endpoints, thereby eliminating key protection complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11503079B2Network security system using statistical object identification
Publication Date: 2022.11.15 INVISINET TECHNOLOGIES LLC
  • US11503079B2 patent drawing
  • US11503079B2 patent drawing
  • US11503079B2 patent drawing

AI summary

Apparatus to enforce network policy based on identity authentication at a network endpoint device by offloading the authentication to a network attached authentication devices is disclosed. The authentication device may use Statistical Object Identification to perform the authentication. The present disclosure greatly reduces the resources needed by the network endpoint device to perform the authentication and eliminates the topological restrictions found in traditional network appliance based approaches.