Dynamic Network Identity Bridge for Cyber Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, as traditional security measures provide a fixed target for attackers.

Innovation Solution

The method involves dynamically modifying identity parameters such as IP addresses and MAC addresses within a computer network using a pseudorandom function, transforming them into false values to obfuscate network machine identities, and varying the location of these modifications to thwart cyber attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network identities and fixed security measures are used, then network infrastructure is simple to implement, but networks become vulnerable to attacks as adversaries can probe and exploit vulnerabilities over time

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork dynamic response
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network identities by continuously changing IP addresses and other network parameters at network nodes. This transforms the static network infrastructure into a dynamic system that can adapt to threats in real-time, resolving the contradiction between reliability and adaptability by making the network both secure and responsive to changing conditions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes network parameters such as IP addresses, port numbers, and routing paths dynamically. This parameter transformation allows the network to maintain security while adapting to new threats, as the changing parameters prevent adversaries from exploiting static vulnerabilities

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic identity parameter modification is implemented, then network security against attacks is enhanced, but system complexity increases due to pseudorandom function implementation

Engineering Contradiction:
Improvenetwork securityVSAvoididentity transformation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses self-service by implementing distributed pseudorandom number generation at each network node using locally available entropy sources. Each node independently generates its own dynamic identities without requiring complex centralized coordination, reducing overall system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a bridge as an intermediary component that coordinates identity transformations between different network segments. This intermediary simplifies the overall system architecture by centralizing the coordination function while allowing individual nodes to maintain simpler local implementation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic reassignment of IP address space is performed, then adversary intelligence gathering is confused, but communication overhead increases due to translation operations

Engineering Contradiction:
Improveadversary detectionVSAvoidpacket translation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-generating pools of valid IP addresses and transformation rules before they are needed. This allows rapid identity changes during actual communication without requiring complex real-time calculations, reducing the time loss associated with packet translation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2813050B1Bridge for communicating with a dynamic computer network
Publication Date: 2019.01.02 HARRIS CORP
  • EP2813050B1 patent drawingFigure 1
  • EP2813050B1 patent drawingFigure 2
  • EP2813050B1 patent drawingFigure 3

AI summary

Method for communicating data from a first computing device (101) in a computer network (100) to a second computing device in a second computer network (124) involves dynamically modifying at a first location (105) in the computer network (100) a plurality of true values (120). The true values correctly represent the plurality of identify parameters. These true values are transformed to false values (122), which incorrectly represent the identity parameters. Subsequently, the identity parameters are modified at a bridge (115) second location to transform the false values back to the true values. The position of the first location varies dynamically as part of this process. Dynamic modification of the identity parameters occurs in accordance with a mission plan that can be modified without interrupting communication of data in the network.