Consent-Contract System for Network Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer networks face inefficiencies and security risks due to devices receiving unwanted network communications, leading to resource wastage and vulnerability to attacks like DoS.

Innovation Solution

Implementing a consent-contract system that creates and enforces consent contracts between devices, allowing network communications only if both the sending and receiving devices have consented, thereby managing and enforcing these contracts at the network-communications layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If devices are allowed to communicate with any other device in the network using global routing tables, then network communication efficiency and accessibility are improved, but receiving devices are exposed to unwanted communications and security risks such as DoS attacks

Engineering Contradiction:
Improvenetwork communication efficiencyVSAvoidunwanted communications and security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing consent contracts between devices before network communications occur. The consent contract system pre-authodes communication permissions, so that when communication requests are made, the receiving device has already granted consent in advance. This prevents unwanted communications from being delivered to receiving devices, thereby maintaining network communication efficiency while blocking security risks at the source.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If receiving devices reject unwanted communication requests, then security is improved, but network resources are wasted due to unnecessary delivery and rejection processing

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork resource waste
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The patent applies the taking out principle by extracting the consent verification process from the traditional reject-based security model. Instead of delivering unwanted communications and then rejecting them, the system extracts and enforces consent contracts at the network layer, preventing unwanted communications from entering the network delivery path. This eliminates the energy waste associated with delivering and then rejecting unwanted traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The consent contract system acts as an intermediary between sending and receiving devices. Rather than direct communication where receiving devices must actively reject unwanted requests, the consent contract intermediary pre-establishes communication permissions, allowing the network to automatically filter traffic based on pre-granted consent. This intermediary mechanism eliminates the need for active rejection processing while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If intermediary devices forward all communications through the network, then network connectivity and accessibility are maintained, but time and resources are wasted on forwarding communications that will ultimately be rejected

Engineering Contradiction:
Improvenetwork connectivityVSAvoidforwarding time for rejected communications
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing consent contracts before communications are forwarded through the network. The consent contract system pre-authodes which device pairs are permitted to communicate, allowing intermediary devices to check consent status before forwarding traffic. This prevents time waste by avoiding the forwarding of communications that would ultimately be rejected, while maintaining full network connectivity for authorized device pairs.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12301729B2Centralized consent vendors for managing network-based consent contracts
Publication Date: 2025.05.13 CISCO TECHNOLOGY INC
  • US12301729B2 patent drawing
  • US12301729B2 patent drawing
  • US12301729B2 patent drawing

AI summary

Techniques for creating consent contracts for devices that indicate whether the devices consent to receiving network-based communications from other devices. Further, the techniques include enforcing the consent contracts such that network-based communications are either allowed or disallowed in the network-communications layer prior to the network communications reaching the devices. Rather than simply allowing a device to communicate with any other device over a network, the techniques described herein include building in consent for network-based communications where the consent is consulted at one or more points in a communication process to make informed decisions about network-based traffic.