Clustered Communication Nodes for Trustworthy Packet Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing packet communication systems face challenges in ensuring trustworthiness of data transmission, particularly in virtual and ad-hoc networks where physical control of nodes is not guaranteed, leading to potential malicious packet leakage between virtual networks due to misconfiguration.

Innovation Solution

The method involves grouping communication nodes into clusters with intra-cluster trust mechanisms and designating multi-cluster-member nodes to route inter-cluster traffic, allowing each cluster to verify the trustworthiness of data elements using security tags or encryption keys, decoupling trust management between clusters and enabling scalable and flexible communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If gateway nodes with fire-wall functions are implemented to police and filter packets, then communication trustworthiness is improved, but device complexity and loss of information increase due to required security features and verification mechanisms

Engineering Contradiction:
Improvecommunication trustworthinessVSAvoidsecurity feature complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is divided into multiple administrative domains, each with its own trust mechanisms. Instead of implementing a single complex gateway system, the patent segments trust verification into domain-specific policies that are simpler to implement and manage within each domain context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Trust verification is customized locally for each administrative domain rather than applying a uniform complex security mechanism everywhere. Each domain can implement trust policies appropriate to its specific requirements, reducing overall system complexity while maintaining trustworthiness.

Inventive Principle:
Principle #3Local quality

2Reliability

If gateway nodes with fire-wall functions are implemented to police and filter packets, then communication trustworthiness is improved, but loss of information increases due to packet dropping and quarantining

Engineering Contradiction:
Improvecommunication trustworthinessVSAvoidpacket loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces trust policies as intermediary mechanisms that mediate between packet filtering requirements and information flow. Instead of directly dropping packets, the system uses policy-based verification that allows legitimate packets to pass while blocking malicious ones, reducing unnecessary packet loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If physical control of nodes is not guaranteed in virtual networks, then network flexibility and adaptability are improved, but communication trustworthiness deteriorates due to potential packet leakage between virtual networks

Engineering Contradiction:
Improvevirtual network flexibilityVSAvoidcommunication trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments virtual networks into isolated administrative domains with distinct trust boundaries. This segmentation prevents packet leakage between virtual networks while maintaining the flexibility of virtualization, as each domain enforces its own trust policies independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Trust policies act as intermediary mechanisms between virtual networks sharing physical infrastructure. These policies verify packet legitimacy at domain boundaries without requiring physical control, enabling flexible virtual network deployment while preventing unauthorized packet leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If a new trust mechanism is designed to be generally applicable and scalable, then adaptability is improved, but device complexity and difficulty of implementation increase

Engineering Contradiction:
Improvetrust mechanism applicabilityVSAvoidtrust mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal trust policy framework that can be applied across different administrative domains and network types. The policy structure is designed to be multi-functional, handling various trust verification scenarios through a common mechanism that adapts to different contexts without requiring domain-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The trust mechanism uses configurable parameters that can be adjusted to fit different network scenarios. By changing policy parameters rather than redesigning the entire trust mechanism, the system achieves scalability and general applicability while keeping implementation complexity manageable.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9591002B2Method and system for providing trustworthiness of communication
Publication Date: 2017.03.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9591002B2 patent drawing
  • US9591002B2 patent drawing
  • US9591002B2 patent drawing

AI summary

A method and system of providing trustworthiness of communication among a plurality of communication nodes is described. This comprises arranging each of said communication nodes to perform a trustworthiness judging operation on received data elements for judging a received packet to be trustworthy or not, grouping said plurality of communication nodes into a plurality of distinguishable clusters, each cluster comprising at least two of said communication nodes, implementing in each respective cluster an intro-cluster trust mechanism such that trustworthiness of data elements sent by any member node of said respective cluster is judgable within said respective cluster, arranging said clusters such that each of said clusters comprises one or more multi-cluster-member nodes that belong to at least two different of said clusters, and muting inter-cluster traffic through said multi-cluster-member nodes.