Mesh Network Security via IP Stack Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mesh networks, securing communications across devices of varying ownership and control is challenging due to the lack of administrative access to all devices, compromising network integrity and potential for increased loss during transactions.

Innovation Solution

A system that analyzes IP stack layer information to determine a user's trust of service information, which is used to assess the security level of a session, thereby determining access levels or additional security measures without requiring administrative access to each device, including limiting transaction amounts or requesting additional verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrative access is required to verify sessions on mesh network devices, then network security can be ensured, but device complexity and ease of operation deteriorate due to the need for administrative access to each device

Engineering Contradiction:
Improvenetwork securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary security verification system that operates at the network layer between devices. This intermediary analyzes IP stack information and trust credentials without requiring direct administrative access to individual devices, thus maintaining security while preserving ease of operation. The intermediary acts as a mediator that verifies sessions using trust-of-service information embedded in network communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of requiring administrative access (manual verification) with an automated electronic system that analyzes IP stack layer information. This substitution uses software-based security verification that automatically processes trust credentials and session information without human intervention, thereby improving ease of operation while maintaining reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If administrative access is required to verify sessions on mesh network devices, then network security can be ensured, but device complexity increases due to the need for administrative access to each device

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security verification system that operates at the network layer between devices. This intermediary analyzes IP stack information and trust credentials without requiring direct administrative access to individual devices, thus maintaining security while preserving ease of operation. The intermediary acts as a mediator that verifies sessions using trust-of-service information embedded in network communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of requiring administrative access (manual verification) with an automated electronic system that analyzes IP stack layer information. This substitution uses software-based security verification that automatically processes trust credentials and session information without human intervention, thereby improving ease of operation while maintaining reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If security screening is implemented on mesh network communications, then network security improves, but productivity decreases due to additional verification steps

Engineering Contradiction:
Improvenetwork securityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary security verification by analyzing trust-of-service information and determining security levels before sessions are fully established. By performing security screening in advance during the connection establishment phase, the system prevents unauthorized sessions from consuming network resources, thereby maintaining productivity while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms where the security verification system continuously monitors session characteristics and adjusts security measures dynamically. Based on analyzed trust credentials and session behavior, the system provides real-time feedback to determine appropriate security levels, allowing legitimate sessions to proceed efficiently while blocking malicious ones, thus balancing security with productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12113801B2System and method for maintaining network security in a mesh network by analyzing IP stack layer information in communications
Publication Date: 2024.10.08 BANK OF AMERICA CORP
  • US12113801B2 patent drawing
  • US12113801B2 patent drawing
  • US12113801B2 patent drawing

AI summary

Systems, methods, and computer program products are provided for monitoring network security in a mesh network. An example method includes receiving trust of service information relating to a user. The trust of service information includes one or more security details associated with at least one of a user device or a user network associated with the user. The method also includes determining a security level of a session involving the user based on the trust of service information relating to the user. The method further includes determining a security protocol for the session based on the determined security level. The security protocol determines at least one of a user access level or an additional security measure. The method still further includes causing an execution of the session based on the security protocol determined.