Migratable Network Nodes with Dynamic Provisioning and Secure Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing networks are constructed component by component, making them inflexible and vulnerable to malicious activity or unwanted scrutiny, as specific nodes can be targeted and remain in fixed locations, leading to security risks and operational inefficiencies.

Innovation Solution

Implementing an on-demand computing network environment with migratable nodes, where resources are dynamically assigned and reconfigured, allowing nodes to be replaced and relocated without disrupting operations, using a network implementation engine to manage resource provisioning and deprovisioning, and establishing secure tunnels for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If nodes are assigned fixed locations in a computing network, then network construction is simplified and stable, but network flexibility deteriorates and security vulnerabilities increase

Engineering Contradiction:
Improvenetwork structure stabilityVSAvoidnetwork flexibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic node provisioning where rim nodes can be automatically created, moved, and deprovisioned based on operational requirements. The system transitions from static fixed-location nodes to dynamic nodes that can change positions and be relocated by an orchestrator, resolving the contradiction between structural stability and network flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The network is segmented into hub nodes and rim nodes with distinct functional roles. Hub nodes provide stable connectivity anchors while rim nodes can be dynamically provisioned and relocated. This segmentation allows the stable core infrastructure to coexist with flexible edge nodes, addressing both stability and adaptability requirements.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If specific nodes are targeted in fixed locations, then network construction is straightforward, but security against malicious activity deteriorates

Engineering Contradiction:
Improvenetwork construction easeVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system employs dynamic node provisioning where rim nodes are automatically created and relocated by an orchestrator, preventing fixed targeting by malicious actors. Nodes transition between provisioned and deprovisioned states, and their locations change over time, making it difficult for attackers to maintain persistent access to specific nodes while keeping network construction straightforward through automated processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an orchestrator as an intermediary that manages node provisioning, movement, and deprovisioning. This intermediary layer abstracts the complexity of security management from individual nodes, allowing straightforward network construction while implementing sophisticated security measures through centralized coordination and automated node lifecycle management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If nodes remain in fixed locations, then network operations are simple and stable, but operational efficiency and security deteriorate due to vulnerability to scrutiny and attacks

Engineering Contradiction:
Improvenetwork operation simplicityVSAvoidoperational efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements automated dynamic node provisioning where the orchestrator manages node creation, movement, and deprovisioning without manual intervention. This maintains operational simplicity through automation while significantly improving security and efficiency by preventing persistent targeting and enabling rapid response to threats through automated node relocation and lifecycle management.

Inventive Principle:
Principle #15Dynamics

4Ease of manufacture

If traditional component-by-component network construction is used, then network assembly is straightforward, but network flexibility and security deteriorate

Engineering Contradiction:
Improvenetwork assembly easeVSAvoidnetwork flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent transforms traditional static network construction into a dynamic process where the orchestrator automatically provisions, configures, and manages rim nodes throughout their lifecycle. Nodes are not merely assembled but dynamically created and managed, enabling straightforward assembly through automation while achieving high flexibility through automated node provisioning and relocation capabilities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12375353B1Systems and methods for providing a computer network having migratable nodes
Publication Date: 2025.07.29 CYBER IP HLDG LLC
  • US12375353B1 patent drawing
  • US12375353B1 patent drawing
  • US12375353B1 patent drawing

AI summary

Systems and methods are provided for a computer-implemented method of implementing an on-demand computing network environment. An example system performs steps including configuring an on-demand computing network, wherein configuring includes assigning a first provisioned resource as a hub node; and assigning one or more second provisioned resources as rim nodes, wherein rim nodes are configured to communicate with one another via the hub node. They example system further moves a particular node of the on-demand computing network by provisioning a new provisioned resource as a new node to replace the particular node and configuring the new provisioned based on parameters associated with the particular node; establishing a tunnel between the new node and a neighboring node of the particular node; and deprovisioning the particular node such that traffic between the new node and the neighboring node traverses the established tunnel.