Replication Network Trust Anchors Against Supervision Frame Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Replication networks are vulnerable to supervision frame injection attacks, which can disrupt network operations by misconfiguring nodes and causing unnecessary traffic or overwhelming the Node Table, leading to system failure.
Innovation Solution
Establish a chain of trust using a trust anchor node to generate security information, authenticate network devices, and encrypt supervision frames with a redundancy network key, ensuring only trusted nodes can communicate within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If supervision frames are transmitted without authentication in a replication network, then network communication is simple and fast, but the network becomes vulnerable to injection attacks that can disrupt operations and overwhelm the Node Table
Solution Approach 1:
The patent implements preliminary authentication of network devices before allowing supervision frame transmission. A trust anchor node generates security information and authenticates devices in advance, creating a chain of trust. This preliminary action prevents unauthorized injection attacks while maintaining network reliability, resolving the contradiction between security and simplicity.
Solution Approach 2:
The patent introduces a trust anchor node as an intermediary that generates security information and establishes authentication chains between network devices. This intermediary enables secure communication without requiring complex peer-to-peer authentication mechanisms, thereby improving network security while managing complexity through a centralized trust management approach.
2Reliability
If authentication mechanisms are implemented to prevent injection attacks, then network security is improved, but the complexity of the network device increases
Solution Approach 1:
Authentication and security information generation are performed in advance by a trust anchor node before devices need to communicate. This preliminary establishment of trust chains reduces the runtime complexity of security verification, as devices already possess the necessary authentication credentials when supervision frames are transmitted.
Solution Approach 2:
Once authenticated, network devices use their own stored security information to independently verify supervision frames without requiring continuous external authentication. This self-service approach reduces the operational complexity of security mechanisms while maintaining strong authentication, resolving the contradiction between security and device complexity.
Data Source
AI summary
Disclosed are systems, apparatuses, methods, and computer-readable media for preventing supervision frame injection attacks in replication networks. A method includes: identifying, by a network device, a trusted network device in a replication network; providing credentials to the trusted network device to validate an identity of the network device; based on authentication of the credential at the trusted network device, receiving security information from the trusted network device that is encrypted with a public key of the network device; and transmitting an onboarding supervision frame encrypted with or signed by the security information, wherein a management device of the replication network updates a trusted peer information based on the onboarding supervision frame.


