Cross-Domain Malicious Node Detection via Encrypted Bulletin Board
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying potentially malicious network elements across multiple administrative domains face challenges in privacy preservation and regulatory compliance, as they often require sharing sensitive information and involve multiple communication rounds between domain operators.
Innovation Solution
A method where domain operators transmit qualifying information about potentially malicious network elements to a functional entity, which provides an alarm only when a predefined number of operators agree, eliminating the need for interactive communication and ensuring privacy through encryption and cyclic group computations, allowing for a centralized or distributed system with high security and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If domain operators share information about potentially malicious nodes with other operators, then detection accuracy and confidence improve, but privacy and secrecy requirements are violated
Solution Approach 1:
The patent introduces a bulletin board as an intermediary entity that receives encrypted warnings from domain operators. The bulletin board enables cross-domain information sharing about malicious nodes without requiring operators to directly share sensitive information, thus maintaining privacy while improving detection accuracy through aggregated evidence from multiple domains.
2Loss of information
If state-of-the-art cryptographic protocols are used for private set intersection, then privacy is preserved, but multiple communication rounds between domain operators are required
Solution Approach 1:
The patent performs preliminary encryption of node identifiers using cyclic group computations before submission to the bulletin board. This preliminary action allows the system to achieve privacy-preserving set intersection without requiring multiple interactive communication rounds, as the encryption and matching can be performed independently and asynchronously.
Solution Approach 2:
The patent replaces the mechanical interactive communication protocol with a mathematical computation system based on cyclic groups. Instead of requiring back-and-forth communication between operators, the system uses cryptographic computations (exponentiation in cyclic groups) to enable private set intersection, substituting physical communication with mathematical operations.
3Ease of operation
If a centralized system collects all qualifying information from operators, then coordination is simplified, but network resource consumption increases
Solution Approach 1:
The patent creates a distributed copy of the warning submission mechanism where each domain operator independently submits encrypted warnings to the bulletin board without needing to coordinate with other operators. This copying approach simplifies coordination at the submission level while the centralized bulletin board efficiently aggregates information, reducing overall network resource consumption compared to full centralized collection protocols.
Data Source
AI summary
A method for identifying potentially malicious network elements within a network is useable in a network which includes a plurality of domains administrated by different operators P1, . . . , Pn. In the method, a functional entity receives qualifying information regarding at least one network element that has been transmitted by at least some of the operators P1, . . . , Pn. The at least one network element is qualified as being potentially malicious. The functional entity provides at least one of an alarm information and an alarm activity based on a predefined number of the operators P1, . . . , Pn having transmitted the qualifying information regarding a same potentially malicious network element to the functional entity.

