Geolocation Packet Header for Node Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack effective traceability and authentication methods to deter and respond to large-scale cyber attacks, particularly in identifying the origin of attacks and differentiating between vandalism, theft, and threats to national security, which hinders the ability to deny network access to rogue users and mitigate denial of service (DoS) and network data interception attacks.

Innovation Solution

A method and system for verifying and geolocating network nodes using a new network packet structure that includes a header portion with security signature and payload data, where enabled network nodes transmit data packets through routers, verify upstream nodes by analyzing header and payload data, and append geolocation information to create a secure and traceable data packet path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network packet structures are used, then network communication is simple and fast, but traceability and authentication of network nodes are insufficient

Engineering Contradiction:
Improvetraceability and authenticationVSAvoidnetwork packet structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network packet is segmented into distinct functional portions: header portion containing routing and security information, and payload data portion containing the actual data. This segmentation allows traceability and authentication features to be added to the header without complicating the overall packet structure, as each portion serves a specific purpose and can be processed independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security signature information and geolocation data are extracted as separate, identifiable elements within the packet structure. The security signature portion is taken out as a distinct component that can be verified independently, enabling authentication without requiring complex integration with the entire packet structure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If network nodes are not verified, then data transmission is fast and uninterrupted, but cyber attacks cannot be deterred or traced

Engineering Contradiction:
Improvecyber security and attack traceabilityVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Network nodes perform verification of upstream nodes in advance before allowing data packets to pass through. The security signature verification and geolocation validation are conducted preliminarily at each network node, ensuring that only authenticated packets are forwarded. This preliminary action prevents unauthorized traffic from propagating through the network, maintaining security without requiring post-detection remediation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If geolocation information is appended to every packet, then node authentication is improved, but packet size and processing overhead increase

Engineering Contradiction:
Improvenode authenticationVSAvoidpacket data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Geolocation information and security signatures are appended only to packets that require verification, rather than uniformly to all packets. Network nodes selectively add these elements based on local conditions such as whether the packet originates from a trusted source or requires authentication. This local quality approach improves node authentication where needed while minimizing unnecessary data volume increases.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If upstream nodes are verified by analyzing header and payload data, then authentication accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidverification processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Network nodes perform partial verification by primarily analyzing the header portion containing security signatures and routing information, rather than thoroughly examining the entire payload data. This partial action approach achieves sufficient authentication accuracy for most packets by focusing verification efforts on the critical security elements in the header, reducing processing time while maintaining adequate authentication precision.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8769267B2Geothentication based on new network packet structure
Publication Date: 2014.07.01 THE BOEING CO
  • US8769267B2 patent drawing
  • US8769267B2 patent drawing
  • US8769267B2 patent drawing

AI summary

A system and method for verifying and/or geolocating network nodes in a network in attenuated environments for cyber and network security applications are disclosed. The system involves an origination network node, a destination network node, and at least one router network node. The origination network node is configured for transmitting a data packet downstream to the destination network node through at least one router network node. The data packet contains a header portion and a payload data portion. At least one of the network nodes is an enabled network node. The enabled network node(s) is configured to verify any of the network nodes that are located upstream from the enabled network node(s) by analyzing the header portion and/or the payload data portion of the data packet.