Node Proximity Verification via Segmented Query-Response Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems fail to effectively distinguish between local and remote nodes, leading to susceptibility to unauthorized access, as conventional query-response protocols do not accurately measure communication time to determine proximity and authenticity.

Innovation Solution

A system and method that uses a query-response protocol with two responses to measure communication time, where the target node provides an immediate and a subsequent response, allowing the source node to determine proximity and authenticity by comparing communication time to a threshold, and integrating this with a node-verification protocol like Open Copy Protection System (OCPS).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional query-response protocols are used to verify node authenticity, then node verification can be performed, but communication time measurement is inaccurate and cannot determine node proximity

Engineering Contradiction:
Improvecommunication time measurement precisionVSAvoidnode proximity determination reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The response message is segmented into two parts: an immediate response sent without processing the query contents, and a second response sent after processing. This segmentation allows the source node to measure only the communication time (first response) separately from the processing time (second response), thereby achieving accurate communication time measurement for proximity determination.

Inventive Principle:
Principle #1Segmentation

2Reliability

If stringent security measures are imposed on all nodes, then network security is enhanced, but local nodes are unnecessarily encumbered with restrictions

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess convenience for local nodes
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different security policies to different nodes based on their proximity characteristics. Local nodes (within communication time threshold) receive standard access permissions with minimal restrictions, while remote nodes (exceeding threshold) are subject to stringent security measures and access restrictions. This differentiated approach enhances overall network security while maintaining ease of operation for authorized local nodes.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If communication time measurement is used to determine node proximity, then local and remote nodes can be distinguished, but the system cannot differentiate between actual communication time and response generation time

Engineering Contradiction:
Improveproximity determination accuracyVSAvoidseparation of communication time and processing time
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The target node sends an immediate response upon receiving the query, before processing the query contents. This preliminary action allows the source node to measure the communication time (transmission and reception delay) independently of the processing time required to generate the authenticated response based on query contents.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7991998B2Secure proximity verification of a node on a network
Publication Date: 2011.08.02 KONINKLIJKE PHILIPS NV
  • US7991998B2 patent drawing
  • US7991998B2 patent drawing

AI summary

A system and method determines the proximity of the target node to the source node from the time required to communicate messages within the node-verification protocol. The node-verification protocol includes a query-response sequence, wherein the source node communicates a query to the target node, and the target node communicates a corresponding response to the source node. The target node is configured to communicate two responses to the query: a first response that is transmitted immediately upon receipt of the query, and a second response based on the contents of the query. The communication time is determined based on the time duration between the transmission of the query and receipt of the first response at the source node and the second response is compared for correspondence to the query, to verify the authenticity of the target node.