Network Watermark for Verifiable Ad-Hoc Path Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security in MANet and ad-hoc networks is vulnerable to attacks such as Sybil, Stolen Identity, Invisible Node, Rush, Blackhole, and Jellyfish, which compromise the integrity of the system, and existing digital and hardware watermarks do not provide adequate security against these threats.

Innovation Solution

A network watermark process that creates a verifiable communications path by sending path data with unique identifiers (UIDs) and class identifiers, allowing nodes to verify and validate the path, ensuring only trusted nodes participate in data transfer, and maintaining a database for reference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital and hardware watermarks are used for network security, then some level of security is provided, but they do not provide adequate security against Sybil, Stolen Identity, Invisible Node, Rush, Blackhole, and Jellyfish attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network path is segmented into multiple hops, each requiring verification of the next node's identity and trustworthiness. This segmentation prevents attacks by ensuring that each segment is validated independently, so compromised nodes cannot affect the entire path.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary verification of node identities and trust relationships before establishing communication paths. By pre-validating nodes and their trust credentials, the system prevents unauthorized nodes from joining attacks before they can execute harmful actions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a verifiable communications path with path data and unique identifiers is implemented, then network security and data integrity are enhanced, but the complexity of the communication process increases

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The path data structure serves multiple functions simultaneously: it identifies the communication path, verifies node identities, maintains trust relationships, and enables security validation. This multi-functionality reduces the need for separate mechanisms, thereby limiting the increase in complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The path data acts as an intermediary that carries verification information between nodes without requiring direct complex interactions. Each node validates the path data from its predecessor, simplifying the verification process through this mediating structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If path verification and validation are required for each communication, then unauthorized access is prevented, but the communication speed and efficiency are reduced

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcommunication speed
Core Design Contradiction:
Object-affected harmful factorsVSSpeed

Solution Approach 1:

Trust relationships and node validations are established in advance before communication occurs. By pre-computing and storing trust credentials, the system avoids performing complex verification during actual communication, thus maintaining security while improving speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each node independently verifies the path data using validation functions that check trust relationships and node identities. This self-service verification eliminates the need for centralized validation, reducing communication overhead and improving speed while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9392020B2Network watermark
Publication Date: 2016.07.12 CODE-X DELAWARE INC
  • US9392020B2 patent drawing
  • US9392020B2 patent drawing
  • US9392020B2 patent drawing

AI summary

A network communications method utilizing a network watermark for providing security in the communications includes creating a verifiable network communications path of nodes through a network for the transfer of information from a first end node to a second end node; verifying the network communications path of nodes, by the first end node, before communicating by the first end node information intended for receipt by the second end node; and once the network communications path of nodes is verified by the first end node, communicating by the first end node, via the verified communications path of nodes, the information intended for receipt by the second end node; wherein the network watermark represents the verifiable network communications path of nodes.