Rendezvous System for Interconnecting Pubsub Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Internet architecture lacks mechanisms for secure data authentication and is vulnerable to flooding attacks, and it does not facilitate efficient interconnection of publish/subscribe networks, which are essential for reliable data retrieval and service access.
Innovation Solution
Implementing a rendezvous system within the IP network to connect local publish/subscribe networks using a Data-Oriented Network Architecture (DONA) that employs cryptographic publication identifiers and Dissemination Handlers to route data securely and efficiently across the Internet, allowing for the interconnection of isolated pubsub networks via the IP network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Internet uses host-to-host applications with IP addresses for point-to-point connections, then connectivity between hosts is established, but the network becomes vulnerable to flooding attacks and lacks data authentication mechanisms
Solution Approach 1:
The patent introduces a publish/subscribe network as an intermediary layer between hosts and the Internet infrastructure. This pubsub network with cryptographic publication identifiers and rendezvous systems mediates data retrieval, providing authentication and protection against flooding attacks while maintaining compatibility with existing IP network infrastructure.
Solution Approach 2:
The patent extracts the authentication and routing functions from the traditional host-to-host model and places them in a separate pubsub network layer. By separating these critical functions into an independent subsystem with its own cryptographic mechanisms, the system gains security without compromising the underlying IP network architecture.
2Adaptability or versatility
If standalone publish/subscribe networks are established as separate islands, then secure data retrieval is achieved within each network, but interconnection between different pubsub networks is not facilitated
Solution Approach 1:
The patent makes the publication identifier system universal across different pubsub networks. By using cryptographic hashes of private keys as publication identifiers that can be recognized across network boundaries, the system enables any pubsub network to subscribe to and retrieve data from any other pubsub network without requiring network-specific protocols or translation mechanisms.
Solution Approach 2:
The patent introduces IP network gateways as intermediaries that connect standalone pubsub networks. These gateways translate between the pubsub protocol and IP network protocols, enabling seamless interconnection while maintaining the security and authentication mechanisms of the underlying pubsub networks.
3Reliability
If the Internet architecture focuses on hosts and endpoints with URLs and IP addresses, then point-to-point connectivity is enabled, but data authentication and secure retrieval mechanisms are lacking
Solution Approach 1:
The patent implements self-service authentication through cryptographic publication identifiers. The publication identifier, being a hash of the publisher's private key, inherently contains authentication information. Verifiers can authenticate data origin without requiring separate authentication protocols or interactions with the publisher, making the authentication process transparent and automatic.
Solution Approach 2:
The patent changes the fundamental parameter used for data identification from host-based identifiers (IP addresses, URLs) to data-based cryptographic identifiers (publication identifiers). This parameter change enables authentication to be embedded in the identifier itself rather than requiring separate authentication mechanisms, simplifying the overall process.
Data Source
AI summary
A method of making data, published on a first publication/subscribe (pubsub) network, available to hosts within a second publication/subscribe network where the networks are interconnected via the Internet. The method comprises registering a publication identity of said data within a rendezvous system located within the Internet, forwarding Subscribe requests associated with said publication identity from said second network to said rendezvous system and, at the rendezvous system, identifying a location of said data within said first network. The Subscribe request can then be forwarded to said first network, and said data delivered from said first network to said second network via the Internet.


