Network Validation Device for Source Path Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Source path validation in packet networks relies on destination trust, making it susceptible to modification, leading to a disproportionate computational burden for digital security responders, which attackers exploit to evade detection.
Innovation Solution
A validation device in a communication network communicates control information bidirectionally via the control plane and accesses message data via the production plane, using key data to verify the validity of signatures attached to packets, ensuring they traversed the network along a valid path from source to destination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If destination trusts the contents of frames and packets received, then source path validation is simplified, but the system becomes susceptible to modification by entities with access to traffic
Solution Approach 1:
The patent introduces an intermediary validation mechanism where network elements (switches/routers) automatically attach digital signatures to packets as they traverse the network. These signatures act as mediators that verify packet integrity and path validity without requiring destination trust assumptions, thus resolving the contradiction between validation simplicity and security reliability
Solution Approach 2:
The patent applies preliminary action by having network elements attach digital signatures to packets proactively as they traverse the network, before the packet reaches the destination. This preliminary validation setup ensures that integrity verification is already in place, eliminating the need for destination-based trust assumptions while maintaining automated validation
2Measurement precision
If digital security responders review traffic logs with hundreds of millions of records, then packet origin and validity can be determined, but the computational and analytical burden becomes disproportionate
Solution Approach 1:
The patent extracts the validation computation from the destination and distributes it throughout the network path. Each network element performs local validation by attaching and verifying digital signatures, extracting the computational burden from centralized destination processing and distributing it across the network path, thus reducing the overload on security responders
Solution Approach 2:
The patent implements self-service validation where network elements automatically perform integrity verification as part of their normal packet forwarding function. The validation is built into the network infrastructure itself, eliminating the need for separate manual security analysis of traffic logs and enabling automated, real-time validation without proportional computational burden on responders
3Object-generated harmful factors
If attackers evade detection by exploiting the computational burden, then packet modification becomes more successful, but network security validation must remain effective
Solution Approach 1:
The patent replaces manual security analysis with automated cryptographic validation. Instead of relying on human responders to analyze traffic logs, the system uses digital signatures and public key infrastructure to automatically verify packet integrity and path validity, making it computationally infeasible for attackers to evade detection while maintaining effective security validation
Data Source
AI summary
A validation device in a communication network is configured to communicate control information bidirectionally via a control plane of the network and access message data via a production plane of the network. The validation device receives key data via the control plane, and accesses a message received via the production plane by a message receiving device. The message includes a signature derived from the first key data. The validation device uses the first key data to check validity of the signature.


