Cross-Domain Malicious Node Detection via Encrypted Bulletin Board

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying potentially malicious network elements across multiple administrative domains face challenges in privacy preservation and regulatory compliance, as they often require sharing sensitive information and involve multiple communication rounds between domain operators.

Innovation Solution

A method where domain operators transmit qualifying information about potentially malicious network elements to a functional entity, which provides an alarm only when a predefined number of operators agree, eliminating the need for interactive communication and ensuring privacy through encryption and cyclic group computations, allowing for a centralized or distributed system with high security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If domain operators share information about potentially malicious nodes with other operators, then detection accuracy and confidence improve, but privacy and secrecy requirements are violated

Engineering Contradiction:
Improvedetection accuracyVSAvoidprivacy loss
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent introduces a bulletin board as an intermediary entity that receives encrypted warnings from domain operators. The bulletin board enables cross-domain information sharing about malicious nodes without requiring operators to directly share sensitive information, thus maintaining privacy while improving detection accuracy through aggregated evidence from multiple domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If state-of-the-art cryptographic protocols are used for private set intersection, then privacy is preserved, but multiple communication rounds between domain operators are required

Engineering Contradiction:
Improveprivacy preservationVSAvoidcommunication time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary encryption of node identifiers using cyclic group computations before submission to the bulletin board. This preliminary action allows the system to achieve privacy-preserving set intersection without requiring multiple interactive communication rounds, as the encryption and matching can be performed independently and asynchronously.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical interactive communication protocol with a mathematical computation system based on cyclic groups. Instead of requiring back-and-forth communication between operators, the system uses cryptographic computations (exponentiation in cyclic groups) to enable private set intersection, substituting physical communication with mathematical operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If a centralized system collects all qualifying information from operators, then coordination is simplified, but network resource consumption increases

Engineering Contradiction:
Improvecoordination simplicityVSAvoidnetwork resource consumption
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent creates a distributed copy of the warning submission mechanism where each domain operator independently submits encrypted warnings to the bulletin board without needing to coordinate with other operators. This copying approach simplifies coordination at the submission level while the centralized bulletin board efficiently aggregates information, reducing overall network resource consumption compared to full centralized collection protocols.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9419994B2Method for identifying potentially malicious network elements within a network using cross-domain collaborative data sharing
Publication Date: 2016.08.16 NEC CORP
  • US9419994B2 patent drawing
  • US9419994B2 patent drawing

AI summary

A method for identifying potentially malicious network elements within a network is useable in a network which includes a plurality of domains administrated by different operators P1, . . . , Pn. In the method, a functional entity receives qualifying information regarding at least one network element that has been transmitted by at least some of the operators P1, . . . , Pn. The at least one network element is qualified as being potentially malicious. The functional entity provides at least one of an alarm information and an alarm activity based on a predefined number of the operators P1, . . . , Pn having transmitted the qualifying information regarding a same potentially malicious network element to the functional entity.