Hardware Assisted Provenance Proof in Named Data Networking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet infrastructure, based on communication networks, is inefficient and error-prone for solving distribution problems, as it does not account for hardware-assisted security, making it difficult to verify the origin of data in content-oriented networks like NDN.

Innovation Solution

Implementing a system with hardware-assisted provenance proof in named data networking (NDN) that uses trusted security zones to ensure data integrity by generating and verifying digital signatures across the network, ensuring that data is from a trusted source and routing path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-assisted security is implemented to verify data origin, then security is improved, but device complexity increases

Engineering Contradiction:
Improvedata origin verificationVSAvoidtrusted security zone
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted security zone as an intermediary hardware component that mediates between the main processor and external communications. This security zone acts as a mediator that verifies data origin and routing path without requiring the entire system to become more complex, thus resolving the contradiction between improved security and increased device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signatures are generated and verified for all data content, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidsignature verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing trusted security zones in hardware before data transmission occurs. The trusted origin and routing path are verified in advance through hardware-based trust relationships, so that when data arrives, the integrity verification is already partially complete, reducing the time penalty associated with digital signature verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If trusted security zones are enabled in all network nodes, then network security is improved, but implementation cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies universality by designing the trusted security zone as a multi-functional hardware component that can operate in various network nodes (clients, servers, routers) with the same basic architecture. This standardized approach allows the same security mechanism to be manufactured and deployed across different device types, reducing overall implementation costs while maintaining network-wide security improvements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9819679B1Hardware assisted provenance proof of named data networking associated to device data, addresses, services, and servers
Publication Date: 2017.11.14 T MOBILE INNOVATIONS LLC
  • US9819679B1 patent drawing
  • US9819679B1 patent drawing
  • US9819679B1 patent drawing

AI summary

A system of delivering data content with hardware assisted provenance proof in named data networking (NDN). The system comprises a data content server with a trusted security zone enabled that is configured to receive the first request message from the first client, and transmit the desired data content based on the name comprised in the first request message and a determination that the first client is trusted and that the routing path from the first client to the data content server is trusted. The system further comprises a signature server with a trusted security zone enabled that is configured to receive the first request message from the first client, generate a digital signature based on the desired data content, and transmit the corresponding digital signature based on a determination that the first client is trusted and that the routing path from the first client to the signature server is trusted.