Agile Node Isolation via Packet Non-Repudiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing ad-hoc, mobile networks without a perimeter defense is challenging due to the decentralized nature of these networks, where no node can fully trust others, and traditional security measures are insufficient against high-intensity cyber-attacks that can compromise nodes, leading to potential mission failure and loss of life.

Innovation Solution

Implementing packet level non-repudiation (PLNR) technology to dynamically reconfigure mobile networks by analyzing packets for authentication headers and certificates, isolating compromised nodes through a security apparatus with modules like PLNR, DISCO, and TATL, which verifies and manages public keys and certificates to prevent unauthorized communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual investigation and incident response are used to secure the network, then security measures can be implemented, but the response time is too slow to prevent mission failure during high-intensity cyber-attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidincident response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing authentication headers with certificates for all nodes before attacks occur. When a compromise is detected, the system immediately isolates the node by revoking its certificate, preventing further damage without requiring manual investigation. This preliminary setup enables automated, instantaneous response to security threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system operates autonomously by automatically detecting compromised nodes through authentication header verification and isolating them by revoking certificates. The system does not require manual investigation or intervention - it self-monitors, self-diagnoses, and self-corrects security breaches in real-time, eliminating the time loss associated with human response.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If perimeter defense is implemented to protect the network, then external attacks can be blocked, but it is insufficient when adversaries have already compromised nodes inside the network

Engineering Contradiction:
Improveexternal cyber-attacksVSAvoidinternal network security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Instead of applying a uniform perimeter defense, the system applies local quality control at each node level. Each node independently verifies authentication headers with certificates, creating localized security checks throughout the network. This enables the system to identify and isolate compromised nodes individually, maintaining security even when some nodes are breached, as the compromise cannot spread to nodes with valid certificates.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If traditional authentication methods are used in decentralized mobile networks, then node identification can be maintained, but computational overhead of generating and verifying e-signatures prevents viable solutions

Engineering Contradiction:
Improvenode authenticationVSAvoidcomputational overhead
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary action by pre-generating and distributing certificates to all nodes before they join the network. This eliminates the need for computationally intensive e-signature generation and verification during normal operations. Nodes simply present their pre-issued certificates for authentication, dramatically reducing computational overhead while maintaining secure node identification in the decentralized mobile network.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11706624B1Agile node isolation through using packet level non-repudiation for mobile networks
Publication Date: 2023.07.18 GRIER JONATHAN
  • US11706624B1 patent drawing
  • US11706624B1 patent drawing
  • US11706624B1 patent drawing

AI summary

Apparatus, systems and methods for agile network isolation through use of packet level non-repudiation (PLNR) are provided. Using a fast cryptography to verify that incoming packets are undeniably being received from the identified source, real-time attack notifications can be independently verified and shared among the network devices to remove compromised nodes from the network. The ability to collaborate among nodes without trust may be achieved via PLNR, to share attack notifications in real-time may be achieved via Telling Attack Layer (TATL), and to establish the identity of an attack in a permanent and binding way may be achieved via DISCOvery (DISCO).