Nested VPN Tunnels for Secure Multicast in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing layered commercial cryptography solutions are inadequate for securing military communications in wireless cooperative broadcast networks, particularly due to their inability to support multicast communications, which are essential for applications like handheld radios and unmanned aerial vehicles (UAVs).

Innovation Solution

The proposed solution involves encrypting datagrams twice in a wireless cooperative broadcast network, using an inner layer key shared among a subset of devices and an outer layer key shared among a superset of devices, with each key being distinct and established through server-centric or serverless group key management protocols, ensuring secure communication by decrypting the datagrams in reverse order at receiving devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If layered commercial cryptography (COTS VPN components) is used to secure communications, then cost is reduced, but multicast communication capability is lost

Engineering Contradiction:
ImprovecostVSAvoidmulticast communication capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements nested VPN tunnels where an inner VPN component encrypts data with its own keys, and an outer VPN component further encrypts the already-encrypted data with separate keys. This multi-layered nesting structure enables multicast communication capability while maintaining cost-effectiveness by using commercial off-the-shelf components in a layered configuration.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If traditional Type 1 cryptographic devices are used, then cryptographic security is improved, but per-unit cost increases significantly

Engineering Contradiction:
Improvecryptographic securityVSAvoidper-unit cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces expensive Type 1 cryptographic devices with commercial off-the-shelf VPN components that are significantly cheaper. While individual COTS components have lower security credentials, the layered configuration of multiple independent COTS VPN components achieves comparable overall security at a fraction of the cost, making encryption feasible for small, inexpensive platforms.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent creates a composite security architecture by combining multiple different COTS VPN components from different vendors into a layered system. This composite approach leverages the strengths of each component while achieving overall cryptographic security that rivals traditional Type 1 devices, but at much lower per-unit cost.

Inventive Principle:
Principle #40Composite materials

3Reliability

If double encryption with nested VPN tunnels is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the encryption system into distinct segmented layers: an inner VPN component and an outer VPN component. Each layer operates independently with its own key management and encryption processes. This segmentation allows each component to be configured and managed separately, reducing overall system complexity despite the enhanced security provided by double encryption.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11929996B2Secure wireless cooperative broadcast networks
Publication Date: 2024.03.12 CALIOLA ENGINEERING LLC
  • US11929996B2 patent drawing
  • US11929996B2 patent drawing
  • US11929996B2 patent drawing

AI summary

Cryptographically secure data communications between layered groups of devices in a wireless cooperative broadcast network encrypts datagrams twice prior to transmission by a source device, first using an inner layer key that is shared by a first group of devices, and second using an outer layer key that is shared by a second group of devices; the devices of the first group being members of the second group. Received datagrams are recovered by first decrypting with the outer layer key and second decrypting with the inner layer key.