Content Tracking Identifiers for Geographical Network Containment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IP data networks are incapable of interpreting network content, leading to an inability to track and enforce geographical containment of network content, which is essential for compliance with export control laws and privacy regulations like GDPR.
Innovation Solution
A secure data network with a network operating system that generates hyperlinked hypercontent objects, including a root data object and message chunks, and encrypts them with a content tracking identifier in the header, enabling geospatial tracking and selective containment within geographical boundaries using virtual sensors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP data networks use opaque payload portions for routing, then network routing capability is maintained, but network content interpretation and geographical tracking capability is lost
Solution Approach 1:
The patent introduces a content tracking identifier as an intermediary element that bridges the opaque IP packet routing mechanism and the need for content awareness. This identifier is embedded within the packet structure and enables intermediate network devices to interpret content attributes without compromising the fundamental opaque routing capability of IP networks.
Solution Approach 2:
The content tracking identifier is nested within the existing IP packet structure, specifically embedded in the payload portion alongside the opaque data. This allows the tracking mechanism to be contained within the packet without altering the external routing interface, enabling content awareness while preserving IP routing simplicity.
2Difficulty of detecting and measuring
If layer 7 switches aggregate payload portions to identify content, then content identification capability is improved, but deployment complexity and awareness of private WAN traffic is reduced
Solution Approach 1:
The patent segments the content identification function from complex layer 7 processing by extracting a simplified content tracking identifier from the payload. This segmentation allows simpler network devices to perform content awareness using the identifier without requiring sophisticated payload aggregation and reassembly capabilities.
Solution Approach 2:
The essential content identification information is extracted from the complex payload structure and condensed into a dedicated content tracking identifier. This extraction removes the burden of processing entire payload portions while retaining the critical content awareness functionality needed for geographical tracking.
3Device complexity
If existing IP networks transmit network content as opaque data, then network infrastructure simplicity is maintained, but geographical containment enforcement capability is lost
Solution Approach 1:
The content tracking identifier is preliminarily embedded in the packet structure at the source, enabling geographical containment enforcement to be prepared in advance. This preliminary action allows network devices to perform containment checks based on pre-established geographical policies without requiring complex real-time analysis of the entire payload.
Data Source
AI summary
In one embodiment, a method comprises: receiving, by a secure executable container executed by a network device, a request to initiate a secure peer-to-peer transfer of a network content item to a second network device in a secure data network; generating a root data object containing metadata describing the network content item and identifying one or more message objects containing respective data chunks of the network content item, the root data object and the data chunks constituting a hyperlinked hypercontent object; generating a secure data packet based on encrypting the root data object or one of the data chunks, the secure data packet of the root data object including a content tracking identifier; and causing a geographical tracking of at least the root data object during transfer of the secure data packet via the secure data network.


