Variable Re-authentication Intervals for Network Security and Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network re-authentication approaches fail to provide increased security, minimize network traffic, differentiate among users, and respond to changes in user profiles and access policies, often compromising security or increasing traffic.

Innovation Solution

A re-authentication process that allows for variable re-authentication intervals based on user or group-specific settings, using an authentication server to set re-authentication timers and a policy server to immediately re-authenticate users upon profile or policy changes, reducing unnecessary re-authentication and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a low re-authentication duration value is set for a port to increase security, then security is improved, but network traffic increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by differentiating re-authentication duration values for different users or groups connected to the same port. Instead of using a single global re-authentication duration for all users on a port, the system assigns specific re-authentication duration values to individual users or groups based on their security requirements. This allows high-security users to have frequent re-authentication while low-security users have less frequent re-authentication, thereby maintaining security for critical users without unnecessarily increasing network traffic for all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the user base into different groups or individuals with distinct re-authentication requirements. By dividing users into separate categories (e.g., high-security, medium-security, low-security groups), the system can apply differentiated re-authentication policies to each segment. This segmentation enables the network to maintain appropriate security levels for each user group while optimizing overall network traffic by avoiding uniform frequent re-authentication across all users.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If a high re-authentication duration value is set for a port to reduce network traffic, then network traffic is minimized, but security is compromised

Engineering Contradiction:
Improvenetwork trafficVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system applies local quality by assigning different re-authentication duration values to different users or groups based on their specific security needs. Users with lower security requirements can have longer re-authentication intervals, reducing network traffic for these users. Meanwhile, users with higher security requirements maintain shorter intervals, ensuring security is not compromised for critical users. This localized differentiation resolves the contradiction by optimizing traffic for non-critical users while maintaining security for critical users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments users into groups with different security classifications, allowing the system to apply appropriate re-authentication frequencies to each segment. Low-security groups experience reduced re-authentication traffic, while high-security groups maintain frequent re-authentication. This segmentation strategy minimizes overall network traffic while preserving security for users who require it, thereby resolving the trade-off between traffic reduction and security maintenance.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If re-authentication duration value is set long to reduce traffic, then network traffic is reduced, but responsiveness to user profile changes is delayed

Engineering Contradiction:
Improvenetwork trafficVSAvoidresponsiveness to profile changes
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent implements dynamics by making re-authentication duration values adaptable and changeable based on user profile updates. When a user's profile or access policy is modified, the system can dynamically adjust the re-authentication duration value for that user, even during an ongoing session. This dynamic adjustment allows the system to maintain long re-authentication intervals for stability and low traffic, while simultaneously responding quickly to profile changes by updating the interval settings, thus resolving the contradiction between traffic reduction and responsiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms to monitor user profile changes and trigger appropriate re-authentication actions. When the authentication server detects that a user's profile or access policy has been modified, it receives feedback about the change and can initiate a re-authentication event or adjust the re-authentication duration value accordingly. This feedback loop ensures that even with longer re-authentication intervals, the system remains responsive to critical profile changes, maintaining security while optimizing network traffic during normal operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8984606B2Re-authentication
Publication Date: 2015.03.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8984606B2 patent drawing
  • US8984606B2 patent drawing
  • US8984606B2 patent drawing

AI summary

In one example, a method of managing access to a network includes receiving a network access request including one or more credentials via an edge device. The one or more user credentials are authenticated, and a database record for a user associated with the one or more user credentials is identified. A re-authentication duration value is obtained from the database record for the user, wherein the re-authentication duration value is pre-assigned to the user or pre-assigned to a group associated with the user. A response comprising the re-authentication duration value is then sent to the edge device.