Decentralized Policy Management for High Security MANETs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing policy-based network management systems for mobile ad-hoc networks (MANETs) lack robust security measures, particularly in decentralized environments, where centralized security approaches are insufficient against insider and external attacks, and policy distribution and enforcement are vulnerable to hijacking and interference.
Innovation Solution
A decentralized policy management system where each node has a policy manager that enforces authentication and authorization, with a deny-by-default policy approach, using secure containers to isolate policy decisions and enforcement, and employing secure protocols for policy distribution to prevent unauthorized access and ensure policy integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized policy control approach is used, then policy management is simplified, but security against insider and external attacks deteriorates
Solution Approach 1:
The patent segments the centralized policy control into distributed policy decision points (PDPs) located at individual network nodes. Each node independently evaluates policies locally, eliminating the single point of failure and reducing vulnerability to attacks while maintaining manageable complexity through standardized policy evaluation procedures.
2Ease of operation
If policy decisions are dispatched over the network, then centralized control is achieved, but vulnerability to decision hijacking and traffic analysis increases
Solution Approach 1:
The patent extracts the policy decision-making function from centralized locations and embeds it directly at each network node. Policy decisions are evaluated locally using locally stored policy rules, eliminating network transmission of decision logic and preventing hijacking while maintaining operational simplicity through automated local evaluation.
Solution Approach 2:
The patent introduces a local policy evaluation module as an intermediary between received policies and network actions. This intermediary component translates received policy decisions into local enforcement actions without exposing decision-making processes to network transmission, thereby preventing traffic analysis and hijacking attempts.
3Device complexity
If a single trusted node is assumed, then policy distribution is simplified, but the ability of an attacker to compromise the whole network increases
Solution Approach 1:
The patent segments the single trusted node assumption into multiple distributed trusted nodes at different network locations. Each node maintains its own policy evaluation capability and trusts only locally verified policies, preventing a single point of compromise while maintaining distribution simplicity through standardized policy propagation mechanisms.
4Reliability
If strict enforcement of communication restrictions is implemented, then security is improved, but resource consumption pressure increases
Solution Approach 1:
The patent applies partial enforcement by implementing communication restrictions only for critical policy-related traffic and authentication messages, while allowing standard data traffic to flow without intensive processing. This selective enforcement maintains security for essential functions while reducing overall resource consumption pressure on nodes.
Data Source
AI summary
A system and method for policy based management for a high security MANET comprises policy managers, each performing policy decision-making and policy enforcement using multiple policies, containers, each related to an application and each container having one policy manager, nodes, each having an infrastructure and at least one container, and dynamic community building blocks associating the containers having a same application, the containers being in different nodes, the associated containers maintained by the dynamic community building blocks on a secure network. Each container can define a security boundary around the node. Each container can be a lightweight virtual machine. The system can also have a special container having a policy manager only evaluating policies for conflicts. In one embodiment, a node can consist of multiple network devices and each network device is a container of its own.


