Network Validation Device for Source Path Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Source path validation in packet networks relies on destination trust, making it susceptible to modification, leading to a disproportionate computational burden for digital security responders, which attackers exploit to evade detection.

Innovation Solution

A validation device in a communication network communicates control information bidirectionally via the control plane and accesses message data via the production plane, using key data to verify the validity of signatures attached to packets, ensuring they traversed the network along a valid path from source to destination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If destination trusts the contents of frames and packets received, then source path validation is simplified, but the system becomes susceptible to modification by entities with access to traffic

Engineering Contradiction:
Improvesource path validationVSAvoidpacket integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary validation mechanism where network elements (switches/routers) automatically attach digital signatures to packets as they traverse the network. These signatures act as mediators that verify packet integrity and path validity without requiring destination trust assumptions, thus resolving the contradiction between validation simplicity and security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by having network elements attach digital signatures to packets proactively as they traverse the network, before the packet reaches the destination. This preliminary validation setup ensures that integrity verification is already in place, eliminating the need for destination-based trust assumptions while maintaining automated validation

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If digital security responders review traffic logs with hundreds of millions of records, then packet origin and validity can be determined, but the computational and analytical burden becomes disproportionate

Engineering Contradiction:
Improvepacket origin determinationVSAvoidsecurity response efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts the validation computation from the destination and distributes it throughout the network path. Each network element performs local validation by attaching and verifying digital signatures, extracting the computational burden from centralized destination processing and distributing it across the network path, thus reducing the overload on security responders

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements self-service validation where network elements automatically perform integrity verification as part of their normal packet forwarding function. The validation is built into the network infrastructure itself, eliminating the need for separate manual security analysis of traffic logs and enabling automated, real-time validation without proportional computational burden on responders

Inventive Principle:
Principle #25Self-service

3Object-generated harmful factors

If attackers evade detection by exploiting the computational burden, then packet modification becomes more successful, but network security validation must remain effective

Engineering Contradiction:
Improvepacket modificationVSAvoidsecurity validation
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The patent replaces manual security analysis with automated cryptographic validation. Instead of relying on human responders to analyze traffic logs, the system uses digital signatures and public key infrastructure to automatically verify packet integrity and path validity, making it computationally infeasible for attackers to evade detection while maintaining effective security validation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11902249B2Device for validating a message conveyed via a network
Publication Date: 2024.02.13 SERAPH SECURITY INC
  • US11902249B2 patent drawing
  • US11902249B2 patent drawing
  • US11902249B2 patent drawing

AI summary

A validation device in a communication network is configured to communicate control information bidirectionally via a control plane of the network and access message data via a production plane of the network. The validation device receives key data via the control plane, and accesses a message received via the production plane by a message receiving device. The message includes a signature derived from the first key data. The validation device uses the first key data to check validity of the signature.