Geolocating Network Nodes via Security Signatures in Attenuated Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber and network security systems face challenges in verifying and geolocating network nodes, especially in attenuated environments, where existing methods are vulnerable to sophisticated attacks and lack clear traceability of originators, leading to difficulties in denying network access to rogue users and identifying attack motives.

Innovation Solution

A system that involves appending a security signature to data packets with geolocation information, using IETF IP Networking protocols and Iridium LEO satellite constellations for authentication, allowing network nodes to verify their location through authentication signals and ranging information, and employing a cyber locate portal for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IP networking protocols are used for data transmission, then network communication speed and efficiency are maintained, but the ability to verify and geolocate network nodes is insufficient, making the system vulnerable to sophisticated attacks

Engineering Contradiction:
Improvenetwork security verificationVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds security signature data structures within existing IP packet headers and routing information fields. The security verification mechanism is nested within the standard IP networking protocol stack, allowing security functions to operate without requiring separate communication channels or replacing existing protocols entirely

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces router network nodes as intermediaries that perform security verification functions. These routers act as mediators between the origination and destination network nodes, executing the security signature verification and geolocation checking without requiring direct complex interactions between the end nodes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security verification mechanisms are added to track and trace network nodes, then the ability to identify attack originators is improved, but the complexity of router implementation and control plane signaling increases

Engineering Contradiction:
Improvenode geolocation accuracyVSAvoidrouter processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs security signature verification and geolocation checking at router network nodes along the transmission path, rather than only at the destination. This preliminary action at intermediate nodes enables earlier detection of unauthorized or rogue nodes, improving measurement precision while distributing the processing load across multiple routers rather than concentrating complexity at one point

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security verification process is segmented into distinct functions: security signature verification, geolocation information extraction, and rogue node identification. Each router network node handles specific segments of this process based on its position in the network path, dividing the overall complexity into manageable modular components

Inventive Principle:
Principle #1Segmentation

3Loss of information

If security signature data is appended to every data packet, then traceability to specific network nodes is improved, but the overhead and processing time for packet handling increases

Engineering Contradiction:
Improvetraceability information completenessVSAvoidpacket processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The security signature data structure is designed to serve multiple functions simultaneously: it provides traceability to specific network nodes, enables geolocation verification, supports rogue node identification, and facilitates security event correlation. This multi-functionality reduces the need for separate data structures for each function, minimizing the overall information overhead added to packets

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying of security signature information from packet metadata and router processing logs to create traceable records without requiring the entire security verification dataset to be transmitted with every packet. Critical security attributes are copied into compact formats that enable rapid processing while maintaining complete traceability information in centralized security event correlation systems

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2715988B1Geolocating network nodes in attenuated environments for cyber and network security applications
Publication Date: 2017.09.13 THE BOEING CO
  • EP2715988B1 patent drawing
  • EP2715988B1 patent drawing

AI summary

A system and method for verifying and/or geolocating network nodes in attenuated environments for cyber and network security applications are disclosed. The system involves an origination network node, a destination network node, and at least one router network node. The origination network node is configured for transmitting a data packet to the destination network node through at least one router network node. The data packet contains a security signature portion, a routing data portion, and a payload data portion. The security signature portion comprises a listing of at least one network node that the data packet travelled through from the origination network node to the destination network node. In addition, the security signature portion comprises geolocation information, identifier information, and timing information for at least one network node in the listing.