Software-Defined Network Perimeter With Dispersive Routing Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Static routing in computer networks exposes data to interception and decryption risks due to the static nature of communication paths, making it vulnerable to hacking and privacy breaches, especially when using public networks.
Innovation Solution
A software-defined network perimeter system that employs secure endpoint devices, dispersive routing, and third-party due diligence to ensure compliance with predefined security standards, using a correlation server to manage access and communication, thereby obscuring data paths and vetting users before network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static routing is used to define communication paths, then network simplicity and ease of operation are improved, but data security and privacy are worsened due to interception and decryption risks
Solution Approach 1:
The patent implements dynamic routing where communication paths are not fixed but change over time. The system randomly selects different paths for each data transmission between source and destination, preventing static route prediction by attackers. This dynamic path selection maintains network operational simplicity while eliminating the security vulnerability of predictable, fixed routes.
Solution Approach 2:
The patent performs preliminary security vetting of network participants before allowing communication. The due diligence process checks security standards, device compliance, and user credentials in advance. Only vetted participants are added to the network, preventing unauthorized or compromised devices from joining and intercepting data transmissions.
2Adaptability or versatility
If public networks are used for communication, then network accessibility and ease of operation are improved, but security and privacy protection are worsened
Solution Approach 1:
The patent introduces an intermediary trusted network that sits between participants and public networks. This intermediary layer provides secure communication channels while allowing access to public network resources. The intermediary enforces security policies, encrypts communications, and filters traffic, enabling public network accessibility without exposing participants directly to hacking vulnerabilities.
Solution Approach 2:
The patent converts the inherent security risks of public networks into benefits through mandatory due diligence and compliance verification. The public network's openness is transformed into an opportunity for comprehensive security screening, where only devices meeting strict security standards can access the network. The potential harm of public network exposure becomes a benefit of rigorous pre-access security validation.
3Ease of operation
If network access is freely granted, then ease of operation and adaptability are improved, but network security and trust are worsened
Solution Approach 1:
The patent performs preliminary security vetting of all network participants before granting access. The due diligence process verifies device security standards, user credentials, and compliance requirements in advance. Only after successful verification are participants added to the network with appropriate access permissions. This preliminary action maintains ease of operation for authorized users while ensuring network trust through pre-validation.
Solution Approach 2:
The patent implements continuous feedback mechanisms to monitor network participant compliance and security status. The system regularly reassesses participant credentials, monitors for security violations, and can revoke access if compliance deteriorates. This feedback loop maintains network trust while allowing operational flexibility, as access is granted conditionally based on ongoing compliance rather than static one-time approval.
Data Source
AI summary
Implementations of a software-defined network perimeter system may include: a security standards server configured to send an installer to a first client machine utilizing an endpoint protection server, a console server configured to route data across a dispersive network where the data is routed between the first client machine and second client machine, a controller configured to electronically couple the first and second client machines to network resources, a first and second endpoint device coupled to the first and second client machines, respectively, and a correlation server coupled to the security standards server, the console server, the controller, and the first and second endpoint devices where the correlation server is configured to match a physical or logical aspect of the client machine to a registration key included in a database of registration keys where the respective endpoint device provides access to the network resources after receiving the registration key.


