Network Switch Session Key Storage for Unauthorized Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face significant security challenges due to predictable network architectures, where hackers target known memory locations, leading to vulnerabilities and increased risk of unauthorized access and downtime.

Innovation Solution

A system and method that utilize an intermediary device along the physical link between end devices to store a session key derived from network session parameters, restricting access based on authorized communication sessions, using a session security engine to manage and authenticate communications through local memory at network switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If network memory locations are stored in known locations (system memory attached to processors or disk storage arrays), then information can be accessed efficiently, but hackers can target these predictable locations and retrieve sensitive information

Engineering Contradiction:
Improveinformation access speedVSAvoidhacker vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent moves security enforcement from the traditional endpoint dimension (individual memory locations at network edges) to a network infrastructure dimension (switches and routers in the middle of network paths). By embedding session security engines and local memory within network infrastructure devices, security is implemented at a different hierarchical level - the network core rather than the endpoint - thereby maintaining fast local access while removing predictability from hacker targets.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces intermediary devices (switches and routers with session security engines) that mediate between endpoints and network resources. These intermediaries store session keys locally and enforce access control by intercepting and validating traffic flows, preventing hackers from directly accessing memory locations while maintaining legitimate access paths. The intermediary acts as a security gatekeeper without blocking normal information flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are updated at each memory location to counter new hacker threats, then security can be maintained, but logistical complexity and downtime increase

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidsecurity update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions across multiple distributed memory locations by consolidating them into centralized session security engines within network infrastructure devices. Instead of managing security at each individual memory location, the system combines all session key management and access control enforcement into unified security modules at switches and routers, dramatically reducing logistical complexity while improving reliability through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal session security engines that can enforce security policies across multiple different memory locations and network resources through a single mechanism. The session key stored in local memory of the intermediary device serves as a universal credential that protects various information resources, eliminating the need for location-specific security updates and enabling centralized security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If session keys are stored in local memory of intermediary devices, then access control is improved, but memory resources are consumed

Engineering Contradiction:
Improveaccess controlVSAvoidmemory resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent employs session keys that are temporary and short-lived, existing only for the duration of specific network sessions. These session keys are stored in local memory of intermediary devices but are discarded after use, replacing the need for permanent, expensive security credentials. This approach provides strong access control while consuming minimal memory resources, as the security data is both inexpensive and transient.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS7818785B2System and method for secure information handling system memory
Publication Date: 2010.10.19 DELL PROD LP
  • US7818785B2 patent drawing
  • US7818785B2 patent drawing
  • US7818785B2 patent drawing

AI summary

Enhanced network security is provided through an intermediate network device, such as a switch or router, which stores in local memory a session key created based on session parameters. Subsequent attempts to communicate information through the session require authorization at the intermediate device by verification of the session key. For example, selected parameters from a protocol data unit are extracted to form a key, such as an IP address, MAC address, VLAN ID, socket number and application fields. Network accessible memory physically located in an infrastructure device provides an alternative repository for session-based information to enhance network communication security.