Network Admission Control for Privacy-Preserving Source Attribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Internet Protocol lacks mechanisms to prevent malicious packets from being transmitted, making it vulnerable to attacks that can disrupt the network by flooding destination nodes with data, even if the packets are eventually blocked, as it continues to transmit all packets until instructed otherwise, leading to resource consumption and potential damage.

Innovation Solution

A new Internet Protocol with a secure and verifiable network identification system and network admission control, where packets are only admitted to the network if approved by the source node, using a device-implemented carrier-independent packet delivery universal addressing protocol with privacy-preserving source node attribution and network admission control, preventing malicious packets from entering the network in the first place.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If Internet Protocol transmits all packets to destination without discrimination, then packet delivery is simple and fast, but network becomes vulnerable to malicious flooding attacks

Engineering Contradiction:
Improvepacket transmission speedVSAvoidnetwork security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary admission control at the source node before packets are transmitted onto the network. The source node evaluates whether to admit packets based on various criteria (traffic type, source/destination addresses, current network state) before transmission begins, preventing malicious packets from entering the network in the first place rather than reacting after detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary admission control mechanism between the packet source and the network transmission system. This intermediary layer acts as a gatekeeper that filters packets based on security policies and network conditions, mediating between the simple transmission requirement and the security requirement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protocols are added on top of Internet Protocol layers, then packet filtering capability is improved, but packets still consume network resources before being blocked

Engineering Contradiction:
Improvepacket filtering capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent moves the filtering action to occur before packets are transmitted onto the network, not after they have already consumed network resources. The admission control at the source node prevents malicious packets from entering the network infrastructure, eliminating wasted resource consumption on blocked packets

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security function from the traditional reactive security protocols and integrates it into the packet transmission process itself at the source node. Rather than having security as a separate layer that reacts to threats, the security control is embedded in the admission decision process before transmission

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network admission control is implemented at source node, then malicious packet transmission is prevented, but device complexity increases

Engineering Contradiction:
Improvemalicious packet preventionVSAvoidsource node complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service admission control where the source node autonomously evaluates and makes admission decisions for its own packets without requiring external authorization for each packet. The source node maintains local state information and applies security policies independently, reducing the need for complex centralized control infrastructure

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent designs the source node to perform multiple functions: normal packet generation, network state monitoring, security policy evaluation, and admission control decision-making. By making the source node multi-functional, the patent consolidates security capabilities into existing network entities rather than requiring separate dedicated security devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9602485B2Network, network node with privacy preserving source attribution and admission control and device implemented method therfor
Publication Date: 2017.03.21 ARCHITECTURE TECH CORP
  • US9602485B2 patent drawing
  • US9602485B2 patent drawing
  • US9602485B2 patent drawing

AI summary

A device implemented, carrier independent packet delivery universal addressing networking protocol for communication over a network between network nodes utilizing a packet. The protocol has an IP stack having layers. At least some of the layers have privacy preserving source node attribution and network admission control. The packet is admitted to the network only if a source node of the network nodes admits the packet.