Network Consent Contracts for Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer networks face inefficiencies and security risks due to devices being able to communicate with all other devices, leading to unwanted communications, resource wastage, and vulnerability to attacks like DOS.

Innovation Solution

Implementing a consent-contract system that creates and enforces contracts indicating whether devices consent to receiving network communications, allowing network devices to allow or disallow communications based on these contracts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices are allowed to communicate with all other devices in the network, then network connectivity and accessibility are improved, but network security and resource efficiency deteriorate due to unwanted communications and DOS attacks

Engineering Contradiction:
Improvenetwork connectivityVSAvoidunwanted communications
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing consent contracts between devices before actual network communications occur. The consent-contract system pre-authodes which devices are permitted to communicate, creating a forward-authorized access control mechanism that prevents unwanted communications before they reach the network infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a consent-contract system as an intermediary layer between network devices. This intermediary maintains and enforces consent contracts, acting as a mediator that determines whether communications should be permitted based on pre-established agreements, thereby filtering traffic before it consumes network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If all network communications are allowed to reach devices, then communication completeness is improved, but network resource efficiency deteriorates due to unnecessary traffic forwarding

Engineering Contradiction:
Improvecommunication completenessVSAvoidnetwork resource efficiency
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The system extracts and filters out unwanted communications at the consent-contract system layer before they enter the network forwarding infrastructure. By removing non-consented traffic early in the communication path, the system prevents unnecessary consumption of network bandwidth, router processing power, and intermediary device resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The consent-contract system performs preliminary filtering of communications based on pre-established consent agreements. This preliminary action occurs before network devices forward traffic, enabling early termination of unwanted communication flows and preventing waste of network resources on communications that will ultimately be rejected.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If devices must reject unwanted communications, then communication control is improved, but network security deteriorates due to exposure to DOS attacks

Engineering Contradiction:
Improvecommunication controlVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies preliminary anti-action by proactively blocking communications from devices that have not established consent contracts. Rather than allowing attacks to reach devices and then rejecting them, the consent-contract system pre-establishes authorization rules that automatically prevent unauthorized communications, including potential DOS attack traffic, from entering the network.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The consent-contract system serves as a security intermediary that sits between potential attackers and target devices. This intermediary enforces consent-based access control, filtering out malicious traffic before it can impact network security or device operations, thereby enhancing reliability while maintaining communication control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250047684A1Creating Network-Based Consent Contracts
Publication Date: 2025.02.06 CISCO TECHNOLOGY INC
  • US20250047684A1 patent drawing
  • US20250047684A1 patent drawing
  • US20250047684A1 patent drawing

AI summary

Techniques for creating consent contracts for devices that indicate whether the devices consent to receiving network-based communications from other devices. Further, the techniques include enforcing the consent contracts such that network-based communications are either allowed or disallowed in the network-communications layer prior to the network communications reaching the devices. Rather than simply allowing a device to communicate with any other device over a network, the techniques described herein include building in consent for network-based communications where the consent is consulted at one or more points in a communication process to make informed decisions about network-based traffic.