Network Traffic Traceability via Direct Interconnect Pairing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic monitoring systems face challenges in determining real-time traceability in high-capacity communications networks, particularly due to the difficulty in authenticating source addresses and the potential for payload amplification attacks, which strain resources and compromise network security.

Innovation Solution

A method involving the provisioning of direct and public service interfaces on a communications network to differentiate and prioritize traffic, using a network traffic almanac to identify legitimate sources and deprioritize suspicious traffic, thereby reducing processing strain and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If stateless transport is used for efficient network communication, then processing speed and scalability are improved, but traceability of network traffic is lost

Engineering Contradiction:
Improveprocessing speedVSAvoidtraceability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing service interface pairings before traffic processing occurs. The network server maintains a pre-configured mapping between public service interfaces and direct service interfaces for each client, allowing immediate traceability determination when traffic arrives without requiring real-time authentication or state tracking.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of service interface pairings that mediate between the public service interface (where traffic enters) and the direct service interface (where traffic is processed). This intermediary layer enables traceability by routing traffic through defined paths while maintaining the efficiency of stateless transport.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If source address authentication is performed for every packet, then traceability is improved, but processing overhead and latency increase

Engineering Contradiction:
ImprovetraceabilityVSAvoidprocessing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent eliminates real-time authentication overhead by performing the traceability setup in advance. Service interface pairings are established beforehand, so when packets arrive, the server can immediately determine their origin and legitimacy by checking against pre-configured pairings without adding latency to the communication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication and traceability verification process from the real-time packet processing path. By separating the setup phase (establishing pairings) from the execution phase (processing traffic), the system removes the time-consuming authentication steps from the critical path of network communication.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If all network traffic is processed equally, then simplicity is maintained, but resource strain increases due to attack traffic

Engineering Contradiction:
Improvesystem simplicityVSAvoidresource capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent applies local quality by treating different traffic differently based on its origin and the service interface it uses. Legitimate traffic arriving on direct service interfaces receives priority processing, while traffic on public service interfaces can be deprioritized or filtered. This localized differentiation maintains simplicity for legitimate users while protecting resources from attacks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying traceability and prioritization only where necessary. Rather than complexing the entire system, it selectively applies interface pairing verification and traffic prioritization to specific service interfaces and client connections, maintaining overall system simplicity while providing targeted protection.

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If DNS servers serve the whole communications network without constraints, then accessibility and performance are improved, but vulnerability to amplification attacks increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidattack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the service interface into public and direct interfaces, allowing DNS servers to maintain broad accessibility through public interfaces while establishing protected direct interfaces for authenticated clients. This segmentation enables the server to serve the whole network while creating specialized paths that reduce vulnerability to amplification attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by giving different security characteristics to different service interfaces. Direct service interfaces have enhanced security through mandatory pairing verification and traffic prioritization, while public service interfaces maintain open accessibility. This localized security approach preserves overall network accessibility while protecting against attacks on specific vulnerable paths.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11522829B2Determining traceability of network traffic over a communications network
Publication Date: 2022.12.06 IDENTITY DIGITAL LTD
  • US11522829B2 patent drawing
  • US11522829B2 patent drawing
  • US11522829B2 patent drawing

AI summary

System and method for determining traceability of network request traffic over a communications network for reducing strain in traffic processing resources, which includes: provisioning a direct interconnect on the communications network between the server and a predefined source, the direct interconnect providing a private service interface, a defined pairings data of the predefined source with the direct interconnect stored in a storage as a network traffic almanac; provisioning a public service interface on the communications network; receiving a request traffic having an address of the predefined source via the public service interface; consulting the defined paring data with the address to determine if the request traffic matches the predefined source; and de-prioritizing processing of the request traffic based on the request traffic being received on the public service interface rather than the direct interconnect, by dynamically applying a prioritize criterion to the second request traffic before generating a response traffic.