Network Node Geolocation Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber and network security systems lack effective methods to trace and deter large-scale cyber attacks, as they often fail to identify the origin of attacks, leading to difficulties in responding to denial of service (DoS) and network data interception attacks.

Innovation Solution

A method and system for verifying and geolocating network nodes using a data packet structure that includes a security signature portion with geolocation information, allowing enabled network nodes to authenticate and tag network nodes, ensuring only verified nodes are part of the data packet path, thereby enhancing traceability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If geolocation information is added to every data packet header to enable traceability of network nodes, then the ability to trace and identify attack origins is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvetraceability precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary geolocation verification of network nodes before data packet transmission. Enabled network nodes authenticate and geolocate upstream nodes in advance, storing verification results that can be quickly referenced during packet transmission, avoiding real-time complex calculations for each packet

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces enabled network nodes as intermediary elements that perform geolocation verification and authentication functions. These intermediary nodes act as trusted third parties that can verify the identity and location of other network nodes, simplifying the overall system architecture by distributing verification responsibilities rather than requiring every node to perform complex authentication independently

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all network nodes are required to verify and authenticate each other, then network security is improved, but the processing time and productivity decrease

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements partial verification where only enabled network nodes perform full authentication and geolocation verification. Non-enabled nodes can transmit data without performing verification, allowing critical security checks to be performed selectively at key points in the network rather than at every node, thus maintaining security while improving overall transmission efficiency

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The verification and authentication functions are extracted from the general data transmission path and concentrated in enabled network nodes. This separation allows the majority of data packets to flow through the network with minimal processing, while only specific packets passing through enabled nodes undergo comprehensive verification, reducing the overall processing time and maintaining productivity

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If geolocation verification is performed for every data packet, then the ability to deter attacks is improved, but the loss of time in data transmission increases

Engineering Contradiction:
Improveattack deterrenceVSAvoidtransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Geolocation verification and authentication are performed in advance before data packet transmission. Enabled nodes verify the geolocation of upstream nodes beforehand and store verification results, so that during actual data transmission, the system can quickly reference pre-verified information rather than performing time-consuming verification for each packet

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs preliminary geolocation verification to prevent unauthorized or malicious nodes from injecting fake location information before they can carry out attacks. By verifying geolocation in advance and establishing trusted relationships, the system creates a preemptive defense mechanism that deters attacks without adding delay to legitimate data transmission

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2885902B1System and method for geothentication
Publication Date: 2018.12.26 THE BOEING CO
  • EP2885902B1 patent drawingFigure 1A
  • EP2885902B1 patent drawingFigure 1B
  • EP2885902B1 patent drawingFigure 1C

AI summary

A system and method for verifying and/or geolocating network nodes in a network. The system involves an origination network node (120), a destination network node (110), and router network nodes (140). The origination network node (120) transmits a data packet downstream to the destination network node through the router network nodes. The data packet contains a header portion (150, 170) and a payload data portion (160). At least one of the network nodes is an enabled network node that verifies any of the network nodes that are located upstream from the enabled network node(s) by analyzing the header portion and/or the payload data portion of the data packet. In particular, geolocation data of upstream network nodes are authenticated (verified).