Encapsulated Network Routing via Brokering Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security strategies for computer network infrastructures fail to ensure mandatory protection against unauthorized access to confidential data, and they make systems vulnerable to external attacks due to open network ports required for service accessibility.

Innovation Solution

A routing method that involves calling up routing information stored in a key computer system, creating a task file with routing information and a task description, and transferring it through a predetermined communication path involving switching computer systems, while keeping the key and target computer systems' network ports closed to external access, allowing only internal communication between encapsulated systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network ports are kept open to allow external access to services, then system accessibility and communication capability are improved, but security against external attacks deteriorates

Engineering Contradiction:
Improvesystem accessibilityVSAvoidvulnerability to external attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary communication mechanism where task files are transferred through a secure routing infrastructure rather than direct network connections. The routing information stored in the key computer system acts as a mediator that enables communication between systems without requiring open network ports on the target systems, thus maintaining accessibility while blocking direct attack vectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the communication functionality from the target computer system by storing routing information externally in a key computer system. This separates the need for network accessibility from the target system itself, allowing the system to remain closed and secure while still enabling controlled communication through external routing data.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional security measures such as access rights and authentication are implemented, then data protection is improved, but mandatory protection against unauthorized access deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidconfidential data exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by storing and validating routing information before any task execution occurs. The routing data is pre-configured in the key computer system with explicit definitions of allowed communication paths, ensuring that only authorized tasks can be routed to target systems. This preventive measure establishes mandatory protection before any potential unauthorized access attempt.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms through the verification of task file validity by the target computer system. The system continuously checks whether incoming tasks conform to the pre-stored routing information, providing real-time validation that reinforces data protection while maintaining controlled accessibility.

Inventive Principle:
Principle #23Feedback

3Productivity

If a communication path is established between computer systems, then task forwarding capability is improved, but security against manipulation deteriorates

Engineering Contradiction:
Improvetask forwarding capabilityVSAvoidmanipulation vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent establishes communication paths in advance by storing routing information in the key computer system before any tasks need to be forwarded. This pre-defined routing infrastructure specifies exactly which systems can communicate and under what conditions, enabling productive task forwarding while preventing manipulation since the communication paths are predetermined and validated.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3152874B1Routing method for forwarding task instructions between computer systems, computer network infrastructure, and computer program product
Publication Date: 2021.04.14 FUJITSU SIEMENS COMP GMBH
  • EP3152874B1 patent drawingFigure 1A
  • EP3152874B1 patent drawingFigure 1B
  • EP3152874B1 patent drawingFigure 2

AI summary

The invention relates to a routing method for forwarding task instructions in a computer network infrastructure. For this purpose, routing information is processed, which defines at least one routing to one or more compulsorily linked computer systems along a communication path between a key computer system, a group made of one or more brokering computer systems, and a target computer system within the computer network infrastructure. A task file, which comprises the routing information, is transmitted by means of the routing information along the communication path from the key computer system by means of the group of brokering computer systems to the target computer system and executed there. The key computer system and also the target computer system keep predetermined network ports closed in such a way that no connection can be externally established to the key computer system or to the target computer system, wherein, however, the key computer system or the target computer system can establish a connection to a brokering computer system in order to store a data file in the brokering computer system or to collect such a data file therefrom.