Dynamic Network Identity Transformation for Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, as traditional security measures provide a fixed target for attackers.

Innovation Solution

Implementing dynamic network address transformation (DYNAT) and moving target technology (MTT) to dynamically modify and vary identity parameters such as IP addresses and MAC addresses within computer networks, using pseudorandom functions and mission plans to confuse adversaries and change communication patterns without interrupting data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network addresses and fixed security measures are used, then network infrastructure is simple and stable, but network security is vulnerable to attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork dynamics
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network address transformation (DYNAT) that continuously changes IP addresses and other network identifiers. Network nodes dynamically assume different identities and roles, transforming from static to dynamic operation. This creates a moving target that adversaries cannot easily map or exploit, directly resolving the vulnerability of static networks while maintaining operational stability through coordinated transformation protocols.

Inventive Principle:
Principle #15Dynamics

2Reliability

If dynamic network address transformation is implemented, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the network into autonomous nodes that each independently perform address transformation and role assumption functions. Rather than requiring a centralized complex control system, each node is segmented to handle its own identity transformation and coordination with neighbors. This distribution of complexity reduces overall system vulnerability and manages complexity through modular, independent units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network nodes autonomously perform address transformation and role assumption without requiring external control for each transformation event. Each node maintains its own transformation state and coordinates independently with other nodes, eliminating the need for complex centralized management infrastructure and reducing overall system complexity while maintaining dynamic security.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If identity parameters are dynamically modified, then adversaries are confused and attack effectiveness is reduced, but data communication overhead increases

Engineering Contradiction:
Improveadversary effectivenessVSAvoidcommunication overhead
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The patent implements periodic address transformation where nodes change identities at predetermined time intervals or after specific numbers of packets. This periodic action creates regular unpredictability that confuses adversaries without requiring continuous transformation. The rhythmic nature of transformations allows receivers to anticipate changes and buffer packets appropriately, reducing communication overhead while maintaining security effectiveness.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8935780B2Mission management for dynamic computer networks
Publication Date: 2015.01.13 HARRIS CORP
  • US8935780B2 patent drawing
  • US8935780B2 patent drawing
  • US8935780B2 patent drawing

AI summary

Method for communicating data in a computer network involves dynamically modifying at a first location in the computer network a plurality of true values. The true values correctly represent the plurality of identify parameters. These true values are transformed to false values, which incorrectly represent the identity parameters. Subsequently, the identity parameters are modified at a second location to transform the false values back to the true values. The position of the first and/or second locations varies dynamically as part of this process. A bridge transforms identity parameter values when communicating outside the network. Dynamic modification of the identity parameters occurs in accordance with a mission plan that can be modified without interrupting communication of data in the network.