Dynamic Encrypted Communication Protocol for Mobile Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networking protocols, such as OSPF and BGP, are inadequate for managing secure communications in mobile, non-terrestrial networks like airborne systems, where rapid node movement and intermittent connectivity lead to vulnerabilities in security and bandwidth constraints, making it difficult to maintain network integrity and security.

Innovation Solution

A network protocol that incorporates dynamic discovery mechanisms, proactive link monitoring, and a mobility index to manage mobile nodes, enabling rapid incorporation of new nodes, rerouting, and secure communication link establishment, while reducing reliance on centralized key management and public key infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional networking protocols (OSPF, BGP) with static security mechanisms are used, then network security can be maintained in static terrestrial networks, but network security becomes vulnerable in mobile non-terrestrial networks with rapid node movement and intermittent connectivity

Engineering Contradiction:
Improvenetwork securityVSAvoidadaptability to mobile environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security mechanisms that adapt to mobile network conditions. Security associations are established dynamically between nodes based on current network state, connectivity conditions, and node mobility patterns. The system continuously updates security parameters and re-establishes encrypted channels as nodes move and connectivity changes, transforming static security protocols into adaptive mobile security solutions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key security parameters dynamically based on network conditions. Encryption keys are regenerated periodically and on-demand based on node movement detection and connectivity status. Security association parameters such as lifetime, rekeying intervals, and authentication methods are adjusted according to the mobility index and network environment, allowing security to remain robust across varying operational conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If digital certificates and public key infrastructure are used for message authentication, then security can be provided in static networks, but bandwidth consumption increases and operation becomes impractical in bandwidth-constrained wireless subnets of non-terrestrial networks

Engineering Contradiction:
Improvemessage authentication securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and removes the heavy public key infrastructure and digital certificate mechanisms from mobile network operations. Instead of relying on bulky certificates for every authentication, the system uses lightweight pre-shared keys and dynamic key derivation. Only essential authentication data is transmitted, and security is maintained through efficient symmetric encryption with keys distributed through optimized channels, eliminating the bandwidth burden of certificate management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs short-lived session keys and temporary security associations that are discarded after use or upon key expiration. Rather than managing long-lived digital certificates, the system generates ephemeral encryption keys for each communication session or time interval, reducing the amount of security data that must be transmitted and stored. This approach minimizes bandwidth consumption while maintaining continuous security through frequent key rotation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If centralized key management servers are used, then key distribution can be controlled, but network operation becomes dependent on continuous connectivity to these servers, which is not available in intermittent connectivity environments

Engineering Contradiction:
Improvekey management controlVSAvoidoperation during intermittent connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary key distribution and caching mechanisms where security keys and authentication credentials are pre-loaded into nodes before they enter the network or during periods of connectivity. Nodes store multiple pre-configured keys and security parameters locally, enabling them to establish secure communications immediately upon network entry without requiring real-time connection to key management servers. This preliminary preparation ensures continuous security operation during intermittent connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables nodes to autonomously manage their own security credentials and generate encryption keys independently. Each node maintains local key rings and can derive session keys from pre-shared secrets without external server intervention. The system implements distributed key management where nodes self-configure security associations based on pre-distributed trust anchors, eliminating dependency on centralized servers and enabling secure operation in disconnected environments.

Inventive Principle:
Principle #25Self-service

4Reliability

If manual configuration of security for each router link is performed, then security can be customized for each connection, but the process becomes time-consuming and complicated for mobile networks with rapidly changing composition

Engineering Contradiction:
Improvecustomized security configurationVSAvoidsecurity configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automated security configuration where nodes autonomously negotiate and establish security associations with neighboring nodes upon connection. The system uses pre-distributed trust anchors and automated key derivation mechanisms to configure encryption parameters, authentication methods, and security policies without manual intervention. Nodes self-configure their security settings based on their identity, the counterparty's identity, and pre-configured security templates, enabling rapid adaptation to mobile network topology changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures security templates, policy frameworks, and trust anchor hierarchies before network operation begins. These preliminary security configurations provide the foundation for automated negotiation and reduce the complexity of real-time security setup. By establishing security policies and key derivation rules in advance, the system enables rapid automated configuration when nodes connect, eliminating the need for manual security setup while maintaining customized security for each link based on pre-established policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10250388B2Methods, networks and nodes for dynamically establishing encrypted communications
Publication Date: 2019.04.02 ARCHITECTURE TECH CORP
  • US10250388B2 patent drawing
  • US10250388B2 patent drawing
  • US10250388B2 patent drawing

AI summary

Methods, networks and nodes for dynamically establishing encrypted communications between a first node having a first identification and a first private key and a second node having a second identification and a second private key. A first signal comprising information indicative of the first identification of the first node is transmitted, then, upon receipt of the first signal by the second node, a second signal comprising information indicative of the second identification of the second node and a first portion of a symmetric key is transmitted, then, upon receipt of the second signal by the first node, a third signal comprising a second portion of the symmetric key is transmitted.