Network Path Reputation Measurement for Compromised Node Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network solutions fail to effectively measure and prevent failures of network elements, such as malicious software attacks or unauthorized access, which can compromise data integrity during transmission.

Innovation Solution

A method for measuring the reputation of paths visiting nodes in a communication network by assigning a security score to each node, calculating a cumulative trust index based on successive scores, and estimating a reputation measurement for the path, allowing for the detection of compromised nodes and paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic engineering solutions are used to control and regulate data transmission, then data routing reliability is improved, but the ability to detect and prevent malicious attacks on network nodes is insufficient

Engineering Contradiction:
Improvedata routing reliabilityVSAvoiddetection of malicious attacks
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by assigning security scores to network nodes in advance before data transmission occurs. These pre-assigned scores are then used to calculate trust indices for transmission paths, enabling the system to proactively identify and avoid compromised nodes rather than detecting attacks only after they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by continuously monitoring and updating security scores of network nodes based on their behavior and reputation. This feedback loop allows the system to adapt to changing security conditions, where nodes that exhibit malicious behavior have their scores reduced, thereby providing ongoing detection and response capabilities.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If separate networks operated by different parties are used together to transmit data, then network versatility and connectivity are improved, but uniform routing and control rules cannot be enforced, reducing transmission reliability

Engineering Contradiction:
Improvenetwork connectivityVSAvoidtransmission reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies universality by creating a standardized security scoring system that can be applied across multiple independent networks operated by different parties. This universal framework allows diverse networks to participate in a common trust evaluation mechanism, enabling uniform security assessment without requiring centralized control or identical network infrastructures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes by dynamically adjusting security scores and trust indices based on observed network behavior. These parameter changes allow the system to adapt to the specific characteristics of different networks while maintaining a consistent evaluation methodology, thereby ensuring reliable transmission across heterogeneous network environments.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If reputation information from particular network elements is not obtained, then system complexity is reduced, but the ability to precisely locate compromised nodes and take corrective action is lost

Engineering Contradiction:
Improvesystem complexityVSAvoidlocation of compromised nodes
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies segmentation by dividing the network into individual evaluatable units (nodes) with distinct security scores. This segmentation allows the system to assess and identify compromised nodes individually rather than treating the entire network as a single entity, thereby achieving precise location of security issues without requiring overly complex centralized monitoring of every packet.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12244644B2Methods and devices for measuring reputation in a communication network
Publication Date: 2025.03.04 ORANGE SA
  • US12244644B2 patent drawing
  • US12244644B2 patent drawing
  • US12244644B2 patent drawing

AI summary

A method for measuring reputation of paths visiting nodes in a communication network and including, for each node visited by a current path of the network: a) assigning a security score for the node; b) estimating a first trust index based on: a cumulative on the current path of the successive scores of the nodes visited by the current path; and a number of nodes visited by the current path, the estimation of the first trust index providing a reputation measurement for the current path.