Multi-Node Network Security Segregating Internal Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data network systems offer inadequate protection against network-based attacks, as they often rely on usernames and passwords that are easily compromised, leaving gaps in security that can be exploited by unauthorized users.

Innovation Solution

A multi-node environment with a dedicated private network is established, utilizing a node system with encryption key management, a network manager system, and a user system to implement double-encryption of data and secure communication protocols, ensuring end-to-end protection by segregating internal communications from public data flows and employing advanced threat detection and encryption techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If usernames and passwords are used to restrict access to network-accessible electronic devices, then access control is provided, but security against network-based attacks is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork-based attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption key management into separate components: a first enterprise key management system, a second enterprise key management system, and local key management systems at different nodes. This segmentation ensures that no single point of failure can compromise the entire security system, and keys are distributed across multiple trusted entities to protect data at rest and in transit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested encryption layers where data is encrypted multiple times with different keys from different enterprise key management systems. The first encryption layer uses keys from the first enterprise key management system, and the second encryption layer uses keys from the second enterprise key management system, creating a nested security structure where each layer protects against different threat vectors.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If simple or common passwords are used, then ease of operation is improved, but security protection is reduced

Engineering Contradiction:
Improvepassword entryVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical approach of username/password authentication with cryptographic key-based access control. Instead of relying on human-memory-based passwords, the system uses hardware-based key management systems that generate and manage encryption keys. Access is controlled through cryptographic protocols that authenticate users without requiring them to remember complex passwords, thus maintaining ease of operation while significantly improving security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If double-encryption is implemented, then security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional enterprise key management systems that handle multiple security operations: generating encryption keys, distributing keys to local key management systems, managing key rotations, and providing authentication services. These centralized key management systems serve multiple purposes across different nodes and encryption layers, reducing the need for separate key management components at each stage and thereby managing complexity while maintaining strong data protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10333905B2System for providing end-to-end protection against network-based attacks
Publication Date: 2019.06.25 OROCK TECHNOLOGIES INC
  • US10333905B2 patent drawing
  • US10333905B2 patent drawing
  • US10333905B2 patent drawing

AI summary

A plurality of system nodes coupled via a dedicated private network is described herein. The nodes offer an end-to-end solution for protecting against network-based attacks. For example, a single node can receive and store user data via a data flow that passes through various components of the node. The node can be designed such that communications internal to the node, such as the transmission of encryption keys, are partitioned or walled off from the components of the node that handle the publicly accessible data flow. The node also includes a key management subsystem to facilitate the use of encryption keys to encrypt user data.