Software-Defined Network Perimeter With Dispersive Routing Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Static routing in computer networks exposes data to interception and decryption risks due to the static nature of communication paths, making it vulnerable to hacking and privacy breaches, especially when using public networks.

Innovation Solution

A software-defined network perimeter system that employs secure endpoint devices, dispersive routing, and third-party due diligence to ensure compliance with predefined security standards, using a correlation server to manage access and communication, thereby obscuring data paths and vetting users before network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static routing is used to define communication paths, then network simplicity and ease of operation are improved, but data security and privacy are worsened due to interception and decryption risks

Engineering Contradiction:
Improvenetwork simplicityVSAvoiddata interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic routing where communication paths are not fixed but change over time. The system randomly selects different paths for each data transmission between source and destination, preventing static route prediction by attackers. This dynamic path selection maintains network operational simplicity while eliminating the security vulnerability of predictable, fixed routes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary security vetting of network participants before allowing communication. The due diligence process checks security standards, device compliance, and user credentials in advance. Only vetted participants are added to the network, preventing unauthorized or compromised devices from joining and intercepting data transmissions.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If public networks are used for communication, then network accessibility and ease of operation are improved, but security and privacy protection are worsened

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidhacking vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary trusted network that sits between participants and public networks. This intermediary layer provides secure communication channels while allowing access to public network resources. The intermediary enforces security policies, encrypts communications, and filters traffic, enabling public network accessibility without exposing participants directly to hacking vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the inherent security risks of public networks into benefits through mandatory due diligence and compliance verification. The public network's openness is transformed into an opportunity for comprehensive security screening, where only devices meeting strict security standards can access the network. The potential harm of public network exposure becomes a benefit of rigorous pre-access security validation.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of operation

If network access is freely granted, then ease of operation and adaptability are improved, but network security and trust are worsened

Engineering Contradiction:
Improvenetwork access convenienceVSAvoidnetwork trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary security vetting of all network participants before granting access. The due diligence process verifies device security standards, user credentials, and compliance requirements in advance. Only after successful verification are participants added to the network with appropriate access permissions. This preliminary action maintains ease of operation for authorized users while ensuring network trust through pre-validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback mechanisms to monitor network participant compliance and security status. The system regularly reassesses participant credentials, monitors for security violations, and can revoke access if compliance deteriorates. This feedback loop maintains network trust while allowing operational flexibility, as access is granted conditionally based on ongoing compliance rather than static one-time approval.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12476974B2Software defined network for creating a trusted network system
Publication Date: 2025.11.18 CLEVERDOME INC
  • US12476974B2 patent drawing
  • US12476974B2 patent drawing
  • US12476974B2 patent drawing

AI summary

Implementations of a software-defined network perimeter system may include: a security standards server configured to send an installer to a first client machine utilizing an endpoint protection server, a console server configured to route data across a dispersive network where the data is routed between the first client machine and second client machine, a controller configured to electronically couple the first and second client machines to network resources, a first and second endpoint device coupled to the first and second client machines, respectively, and a correlation server coupled to the security standards server, the console server, the controller, and the first and second endpoint devices where the correlation server is configured to match a physical or logical aspect of the client machine to a registration key included in a database of registration keys where the respective endpoint device provides access to the network resources after receiving the registration key.