Network Consent Contracts for Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer networks face inefficiencies and security risks due to devices being able to communicate with all other devices, leading to unwanted communications, resource wastage, and vulnerability to attacks like DOS.
Innovation Solution
Implementing a consent-contract system that creates and enforces contracts indicating whether devices consent to receiving network communications, allowing network devices to allow or disallow communications based on these contracts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices are allowed to communicate with all other devices in the network, then network connectivity and accessibility are improved, but network security and resource efficiency deteriorate due to unwanted communications and DOS attacks
Solution Approach 1:
The system performs preliminary actions by establishing consent contracts between devices before actual network communications occur. The consent-contract system pre-authodes which devices are permitted to communicate, creating a forward-authorized access control mechanism that prevents unwanted communications before they reach the network infrastructure.
Solution Approach 2:
The patent introduces a consent-contract system as an intermediary layer between network devices. This intermediary maintains and enforces consent contracts, acting as a mediator that determines whether communications should be permitted based on pre-established agreements, thereby filtering traffic before it consumes network resources.
2Loss of information
If all network communications are allowed to reach devices, then communication completeness is improved, but network resource efficiency deteriorates due to unnecessary traffic forwarding
Solution Approach 1:
The system extracts and filters out unwanted communications at the consent-contract system layer before they enter the network forwarding infrastructure. By removing non-consented traffic early in the communication path, the system prevents unnecessary consumption of network bandwidth, router processing power, and intermediary device resources.
Solution Approach 2:
The consent-contract system performs preliminary filtering of communications based on pre-established consent agreements. This preliminary action occurs before network devices forward traffic, enabling early termination of unwanted communication flows and preventing waste of network resources on communications that will ultimately be rejected.
3Ease of operation
If devices must reject unwanted communications, then communication control is improved, but network security deteriorates due to exposure to DOS attacks
Solution Approach 1:
The system applies preliminary anti-action by proactively blocking communications from devices that have not established consent contracts. Rather than allowing attacks to reach devices and then rejecting them, the consent-contract system pre-establishes authorization rules that automatically prevent unauthorized communications, including potential DOS attack traffic, from entering the network.
Solution Approach 2:
The consent-contract system serves as a security intermediary that sits between potential attackers and target devices. This intermediary enforces consent-based access control, filtering out malicious traffic before it can impact network security or device operations, thereby enhancing reliability while maintaining communication control.
Data Source
AI summary
Techniques for creating consent contracts for devices that indicate whether the devices consent to receiving network-based communications from other devices. Further, the techniques include enforcing the consent contracts such that network-based communications are either allowed or disallowed in the network-communications layer prior to the network communications reaching the devices. Rather than simply allowing a device to communicate with any other device over a network, the techniques described herein include building in consent for network-based communications where the consent is consulted at one or more points in a communication process to make informed decisions about network-based traffic.


