Network Interface Device Provenance Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network interface devices lack effective mechanisms to ensure data provenance and security across multiple network devices, leading to potential breaches in data integrity and compliance with geographic and security requirements, especially in virtualized cloud infrastructure.

Innovation Solution

Incorporating network interface devices (NIDs) that add provenance information to packets as they pass through each device, creating a digest that includes timestamp and location data, which is then analyzed by an analytics function to enforce security rules, detect anomalies, and ensure compliance with service level agreements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network interface devices add provenance information to packets as they pass through each device, then data provenance tracking and security monitoring are improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata provenance trackingVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The provenance tracking system is segmented into modular components: individual network interface devices each add their own provenance information to packets independently, and separate analytics functions process the accumulated provenance data. This segmentation allows each device to perform a simple, standardized operation without requiring complex integrated systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Provenance information acts as an intermediary data structure that is added to packets as they traverse network devices. This intermediary mechanism enables tracking and monitoring without requiring direct complex interactions between devices, as each device simply appends its provenance information to the existing packet data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network interface devices create and analyze provenance digests in real-time, then security monitoring and anomaly detection are improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Network interface devices perform preliminary action by adding provenance information to packets as they pass through each device in the network path. This incremental accumulation of provenance data occurs in real-time during normal packet forwarding, so that when the packet reaches its destination or is monitored, the complete provenance trail is already assembled, eliminating the need for retrospective data collection.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If provenance information is added to every packet at each network device, then data integrity verification is improved, but network traffic overhead and bandwidth consumption increase

Engineering Contradiction:
Improvedata integrity verificationVSAvoidnetwork traffic overhead
Core Design Contradiction:
Manufacturing precisionVSQuantity of substance

Solution Approach 1:

The provenance information mechanism uses a copying approach where each network interface device creates a copy of its identification and relevant metadata, appending it to the packet's provenance section. This copying method ensures data integrity verification capability while keeping the overhead manageable, as only essential provenance data is replicated rather than full device states or configurations.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3462709B1A network interface device
Publication Date: 2023.06.07 XILINX INC
  • EP3462709B1 patent drawingFigure 1
  • EP3462709B1 patent drawingFigure 2
  • EP3462709B1 patent drawingFigure 3

AI summary

A network interface device is provided in a first device. The network interface device comprises an interface configured to receive a first input from a network. The network interface device also has at least one processor configured to provide an output in dependence on contents of the first input and provenance information which uniquely identifies the network interface device, the output being output via the interface to the network.