Dynamic Multi-Network Security Controls for Encrypted Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security approaches are rendered ineffective by the increased use of encrypted transport and multi-network communications, making it challenging to detect and prevent malicious network traffic across communication networks.

Innovation Solution

A system comprising a network controller device that receives reports of malicious network traffic from one communication network and identifies the source within a distinct communication network, causing a control device associated with the source network to prevent the transmission of malicious traffic outside of its network for a defined time interval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security approaches are used, then network security can be maintained in traditional environments, but effectiveness is reduced in multi-network encrypted communication environments

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidadaptability to encrypted multi-network traffic
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the multi-network environment into distinct network domains (first communication network, second communication network, IP network) and implements security controls at each segment. Network equipment in each network can independently identify and report malicious traffic from its own network, enabling targeted security responses without affecting other networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary reporting mechanism where network equipment in one network can report malicious traffic information to network equipment in another network via the IP network. This intermediary approach enables cross-network security cooperation while maintaining network independence and encrypted communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network equipment blocks malicious traffic from other networks, then security is improved, but false positives may occur without proper identification mechanisms

Engineering Contradiction:
Improvesecurity control accuracyVSAvoidcross-network identification and reporting mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary identification and reporting actions before blocking occurs. Network equipment first identifies malicious traffic, then reports it to other networks through the standardized reporting mechanism. This preliminary action ensures accurate identification and reduces false positives by establishing a verification process before enforcement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of traffic identification from local-only detection to cross-network reporting with standardized parameters. The reporting mechanism uses standardized parameters to describe malicious traffic characteristics, enabling accurate identification and blocking decisions across different networks without requiring complex local analysis in each network.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security controls are implemented across multiple networks, then overall network security is enhanced, but response time and coordination complexity increase

Engineering Contradiction:
Improvemulti-network security coverageVSAvoidmalicious traffic response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent establishes continuous security monitoring and reporting across all networks. Network equipment continuously identifies malicious traffic and reports it through the IP network, enabling uninterrupted security coverage. The standardized reporting mechanism ensures continuous information flow between networks, maintaining security awareness without interruption.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent implements a feedback mechanism where network equipment receives reports about malicious traffic from other networks and automatically enforces blocking controls. This closed-loop feedback system reduces response time by automating the identification-reporting-blocking process, eliminating manual coordination delays while maintaining comprehensive multi-network security coverage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250202915A1Dynamic multi-network security controls
Publication Date: 2025.06.19 AT&T INTELLECTUAL PROPERTY I L P
  • US20250202915A1 patent drawing
  • US20250202915A1 patent drawing
  • US20250202915A1 patent drawing

AI summary

Dynamic multi-network security controls are provided herein. A method can include receiving a report of malicious network traffic observed by first network equipment operating in a first communication network, where the report indicates a second communication network distinct from the first communication network as an originating network of the malicious network traffic, identifying second network equipment operating in the second communication network as a source of the malicious network traffic, and based on the identifying, blocking communications from the second network equipment for a defined time interval.