Router Layered Encryption Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current router technologies lack robust security measures, particularly in high-risk environments, as they often require only a single set of credentials for initialization, leaving them vulnerable to unauthorized access and data breaches.

Innovation Solution

Implementing a multi-layered security approach for router initialization, requiring two sets of credentials: the first for unlocking full-disk encryption and booting the firmware, and the second for accessing settings, using software-based full disk encryption (SWFDE) and file-based encryption to protect sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single set of credentials is used for router initialization, then the ease of operation is improved, but the security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the authentication process into two distinct phases: Phase 1 uses a first set of credentials (username/password) to unlock full-disk encryption and boot the firmware, while Phase 2 uses a second set of credentials (passphrase) to unlock file-based encryption and access router settings. This segmentation of authentication into multiple stages directly resolves the contradiction by improving security through layered credentials while maintaining operational ease through automated phase transitions.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-layered encryption is implemented, then the security is improved, but the device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system is segmented into two independent layers: full-disk encryption protecting the firmware and file-based encryption protecting the settings. Each layer operates independently with its own credentials, allowing the system to achieve enhanced security while managing complexity through modular design where each encryption layer can be implemented and maintained separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary encryption of both the firmware (full-disk encryption) and settings (file-based encryption) before the router becomes operational. The boot loader is pre-configured to automatically perform Phase 1 authentication and decryption, and the firmware is pre-configured to perform Phase 2 authentication, eliminating the need for manual encryption management and reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If credentials are stored in plaintext, then the ease of operation is improved, but the vulnerability to unauthorized access is worsened

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by encrypting credentials and sensitive data before they can be accessed by potential attackers. The boot loader encrypts full-disk data using credentials, and the firmware encrypts settings files using a separate passphrase. This pre-encryption approach prevents unauthorized access even if physical access to the router is obtained, while the encryption keys are automatically provided during legitimate boot sequences.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces encryption algorithms as intermediaries between the stored credentials and the actual data. Instead of storing plaintext credentials that could be directly accessed, the system uses cryptographic intermediaries (encryption algorithms and key management) to transform credentials into protected forms, adding a security layer without preventing legitimate access through automated authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11068600B2Apparatus and method for secure router with layered encryption
Publication Date: 2021.07.20 SIGMA DEFENSE SYST LLC
  • US11068600B2 patent drawing
  • US11068600B2 patent drawing
  • US11068600B2 patent drawing

AI summary

A system, method, and apparatus for secure router operation and initialization. A router may require at least two sets of credentials at different phases of initialization, thereby adhering to a multi-layered security approach. In a first phase of a router initializing for operation, a boot loader of the router may require a first authentication in order to unlock the full-disk encryption and commence booting into firmware. In a second phase, the firmware of the router may require second authentication to continue the initialization and to unlock the file-based encryption and access the settings of the router, after which the router may be fully operational.