Gateway Selective Tunneling for Secure Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless routers lack secure communication protocols, making network traffic vulnerable to monitoring and surveillance, which is not addressed effectively by existing technologies.

Innovation Solution

A gateway system that establishes both secured and non-secured communication channels, selectively forwarding data packets based on attributes such as source and destination addresses and communication protocols, using encryption and decryption to ensure secure data transmission while allowing non-secure communication for certain data packets directly to the remote network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional wireless routers are used to provide internet access, then network connectivity is achieved, but communication security is compromised due to lack of encryption and monitoring vulnerability

Engineering Contradiction:
Improvecommunication securityVSAvoidtraffic monitoring and surveillance
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary device (secure router with encryption module) between the wireless router and network traffic. This intermediary intercepts traffic, encrypts it using cryptographic algorithms, and forwards it to the network, thereby protecting communications from monitoring while maintaining network connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter of network communications by implementing encryption transformations. The encryption module applies cryptographic algorithms to transform plaintext traffic into ciphertext, fundamentally altering the security characteristics of the communication channel

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all communications are routed through secured channels with encryption, then security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidgateway system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing selective encryption based on traffic characteristics. The gateway device analyzes communication attributes and applies encryption only to specific types of traffic that require security protection, leaving other traffic to pass through unchanged, thereby reducing overall system complexity

Inventive Principle:
Principle #3Local quality

3Reliability

If selective forwarding based on communication attributes is implemented, then security is enhanced for sensitive data, but processing time and computational resources increase

Engineering Contradiction:
Improvedata protectionVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial action by applying security measures only to portions of traffic that require protection. The gateway device performs partial encryption on sensitive data fields while leaving other data unchanged, reducing the overall computational burden and processing time

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10959100B1Secured communications routing in a network
Publication Date: 2021.03.23 CHARTER COMM OPERATING LLC
  • US10959100B1 patent drawing
  • US10959100B1 patent drawing
  • US10959100B1 patent drawing

AI summary

Gateway hardware/software (such as associated with a router in a subscriber domain) provides multiple communication devices access to a remote network. During operation, the gateway hardware establishes a secured tunnel between the gateway hardware and a remote communication device over a shared communication link. The gateway hardware also establishes a non-secure channel over the shared communication link. The gateway hardware analyzes communications received from multiple communication devices; the communications are destined for delivery to recipients in the remote network. Depending on attributes of the received communications, the gateway hardware selectively forwards each of the received communications over the secured tunnel or the non-secure channel.