Decentralized Policy Management for High Security MANETs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing policy-based network management systems for mobile ad-hoc networks (MANETs) lack robust security measures, particularly in decentralized environments, where centralized security approaches are insufficient against insider and external attacks, and policy distribution and enforcement are vulnerable to hijacking and interference.

Innovation Solution

A decentralized policy management system where each node has a policy manager that enforces authentication and authorization, with a deny-by-default policy approach, using secure containers to isolate policy decisions and enforcement, and employing secure protocols for policy distribution to prevent unauthorized access and ensure policy integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized policy control approach is used, then policy management is simplified, but security against insider and external attacks deteriorates

Engineering Contradiction:
Improvepolicy management complexityVSAvoidsecurity against attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized policy control into distributed policy decision points (PDPs) located at individual network nodes. Each node independently evaluates policies locally, eliminating the single point of failure and reducing vulnerability to attacks while maintaining manageable complexity through standardized policy evaluation procedures.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If policy decisions are dispatched over the network, then centralized control is achieved, but vulnerability to decision hijacking and traffic analysis increases

Engineering Contradiction:
Improvecentralized control capabilityVSAvoiddecision hijacking and traffic analysis
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the policy decision-making function from centralized locations and embeds it directly at each network node. Policy decisions are evaluated locally using locally stored policy rules, eliminating network transmission of decision logic and preventing hijacking while maintaining operational simplicity through automated local evaluation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a local policy evaluation module as an intermediary between received policies and network actions. This intermediary component translates received policy decisions into local enforcement actions without exposing decision-making processes to network transmission, thereby preventing traffic analysis and hijacking attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single trusted node is assumed, then policy distribution is simplified, but the ability of an attacker to compromise the whole network increases

Engineering Contradiction:
Improvepolicy distribution complexityVSAvoidnetwork compromise risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the single trusted node assumption into multiple distributed trusted nodes at different network locations. Each node maintains its own policy evaluation capability and trusts only locally verified policies, preventing a single point of compromise while maintaining distribution simplicity through standardized policy propagation mechanisms.

Inventive Principle:
Principle #1Segmentation

4Reliability

If strict enforcement of communication restrictions is implemented, then security is improved, but resource consumption pressure increases

Engineering Contradiction:
Improvecommunication securityVSAvoidnode resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial enforcement by implementing communication restrictions only for critical policy-related traffic and authentication messages, while allowing standard data traffic to flow without intensive processing. This selective enforcement maintains security for essential functions while reducing overall resource consumption pressure on nodes.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8769068B2System and method for policy based management for a high security MANET
Publication Date: 2014.07.01 TELCORDIA TECHNOLOGIES INC
  • US8769068B2 patent drawing
  • US8769068B2 patent drawing
  • US8769068B2 patent drawing

AI summary

A system and method for policy based management for a high security MANET comprises policy managers, each performing policy decision-making and policy enforcement using multiple policies, containers, each related to an application and each container having one policy manager, nodes, each having an infrastructure and at least one container, and dynamic community building blocks associating the containers having a same application, the containers being in different nodes, the associated containers maintained by the dynamic community building blocks on a secure network. Each container can define a security boundary around the node. Each container can be a lightweight virtual machine. The system can also have a special container having a policy manager only evaluating policies for conflicts. In one embodiment, a node can consist of multiple network devices and each network device is a container of its own.