Burst Time Plan Dummy Slots for Satellite Traffic Pattern Concealment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication network security techniques, such as encryption, do not effectively hide traffic patterns, allowing eavesdroppers to detect communication patterns and activity levels, particularly in satellite communication systems where longer distances increase susceptibility to interception.
Innovation Solution
A communication network hub generates a burst time plan with allocation information that includes dummy acquisition and contention time slots, along with real and empty slots, to obscure actual communication patterns, using timing, frequency, and power level offsets to mimic real and dummy transmissions, making it difficult for eavesdroppers to distinguish between them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect communication content, then security against content interception is improved, but traffic patterns remain detectable by eavesdroppers
Solution Approach 1:
The patent applies the concept of changing apparent characteristics by introducing dummy traffic that mimics real traffic patterns. The dummy packets are designed to have similar timing, frequency, and power level characteristics as genuine communications, making it difficult for eavesdroppers to distinguish between real and dummy traffic, thereby hiding actual communication patterns while maintaining encryption
Solution Approach 2:
The patent creates copies of real traffic patterns by generating dummy packets that replicate the temporal, spectral, and power characteristics of genuine communications. These dummy copies are transmitted alongside or instead of real traffic, allowing the system to maintain normal communication while obscuring actual traffic patterns from observers
2Reliability
If dummy traffic is introduced to hide communication patterns, then traffic pattern detection by eavesdroppers is reduced, but network bandwidth is consumed by non-productive transmissions
Solution Approach 1:
The patent implements partial dummy traffic insertion rather than complete masking. By strategically inserting dummy packets at certain probability levels and not in all time slots, the system achieves sufficient traffic pattern obscuration while minimizing unnecessary bandwidth consumption. The dummy traffic is introduced at levels that provide security benefits without fully saturating the communication channel
Solution Approach 2:
The patent dynamically adjusts parameters of dummy traffic including insertion probability, packet size, timing intervals, and power levels. By varying these parameters based on network conditions and security requirements, the system optimizes the balance between TRANSEC effectiveness and bandwidth efficiency, consuming only the necessary amount of resources to achieve the desired level of protection
3Productivity
If acquisition time slots are allocated to all remote terminals, then network acquisition efficiency is improved, but traffic patterns become predictable to eavesdroppers
Solution Approach 1:
The patent introduces asymmetry in time slot allocation by assigning dummy acquisition time slots to already-acquired remote terminals in addition to their real acquisition slots. This creates an asymmetric pattern where terminals have both genuine acquisition opportunities and dummy ones, making it difficult for eavesdroppers to predict which slots will contain real acquisition traffic versus dummy traffic, thereby obscuring acquisition patterns while maintaining efficient access
Data Source
AI summary
An apparatus and method of communication in a network includes a hub having a burst time plan generating section to generate a burst time plan including time slot allocation information that allocated transmission time slots in a subsequent frame to remote terminals. The allocation information identifies at least one time slot in the subsequent frame as a dummy time slot assigned to at least one remote terminal already acquired in the network. The hub also includes a transmitter to transmit the burst time plan including the allocation information. A corresponding remote terminal and computer readable media are also discussed.


