Hardware Assisted Provenance Proof in Named Data Networking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Internet infrastructure, based on communication networks, is inefficient and error-prone for solving distribution problems, as it does not account for hardware-assisted security, making it difficult to verify the origin of data in content-oriented networks like NDN.
Innovation Solution
Implementing a system with hardware-assisted provenance proof in named data networking (NDN) that uses trusted security zones to ensure data integrity by generating and verifying digital signatures across the network, ensuring that data is from a trusted source and routing path.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-assisted security is implemented to verify data origin, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces a trusted security zone as an intermediary hardware component that mediates between the main processor and external communications. This security zone acts as a mediator that verifies data origin and routing path without requiring the entire system to become more complex, thus resolving the contradiction between improved security and increased device complexity.
2Reliability
If digital signatures are generated and verified for all data content, then data integrity is improved, but processing time increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing trusted security zones in hardware before data transmission occurs. The trusted origin and routing path are verified in advance through hardware-based trust relationships, so that when data arrives, the integrity verification is already partially complete, reducing the time penalty associated with digital signature verification.
3Reliability
If trusted security zones are enabled in all network nodes, then network security is improved, but implementation cost increases
Solution Approach 1:
The patent applies universality by designing the trusted security zone as a multi-functional hardware component that can operate in various network nodes (clients, servers, routers) with the same basic architecture. This standardized approach allows the same security mechanism to be manufactured and deployed across different device types, reducing overall implementation costs while maintaining network-wide security improvements.
Data Source
AI summary
A system of delivering data content with hardware assisted provenance proof in named data networking (NDN). The system comprises a data content server with a trusted security zone enabled that is configured to receive the first request message from the first client, and transmit the desired data content based on the name comprised in the first request message and a determination that the first client is trusted and that the routing path from the first client to the data content server is trusted. The system further comprises a signature server with a trusted security zone enabled that is configured to receive the first request message from the first client, generate a digital signature based on the desired data content, and transmit the corresponding digital signature based on a determination that the first client is trusted and that the routing path from the first client to the signature server is trusted.


