Secure Network Architecture via Dedicated Security Gateway Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wired local area networks lack effective data security measures, leading to hidden security dangers and increased computing load on switch devices, with existing methods like hop-by-hop encryption causing transmission delays and inefficiencies.
Innovation Solution
A method for establishing a secure network architecture through identity authentication and shared key negotiation between nodes, constructing a three-stage secure communication process using shared keys between switch devices to ensure secure data transmission without the need for static key pairs or hop-by-hop encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hop-by-hop encryption is implemented to ensure data security, then network security is improved, but computing load on switch devices increases and transmission delay increases
Solution Approach 1:
The patent segments the encryption process by introducing dedicated security gateway nodes that handle encryption/decryption operations, separating this function from regular switch devices. This allows switch devices to forward packets without performing encryption operations, reducing their computing load and transmission delay while maintaining security through the gateway nodes.
Solution Approach 2:
The patent introduces security gateway nodes as intermediary components between the data transmission path and the encryption/decryption operations. These gateways act as mediators that handle the computationally intensive security functions, allowing the main transmission path to operate efficiently without security-related delays.
2Reliability
If static key pairs are distributed to all nodes to establish session keys, then secure communication between nodes is achieved, but key distribution and updating processes become extremely complicated
Solution Approach 1:
The patent extracts the key distribution function from the general node-to-node communication and concentrates it in dedicated security gateway nodes. These gateways maintain and manage the key pairs, extracting the complexity of key management from the regular communication process and centralizing it in specialized components.
Solution Approach 2:
The patent implements a self-service key generation mechanism where security gateway nodes automatically generate and manage key pairs for themselves and other gateways. This eliminates the need for manual or complex external key distribution systems, as the gateways service their own key management needs autonomously.
Data Source
AI summary
A method for establishing a secure network architecture, a method and system for secure communication are provided. The method for establishing a secure network architecture includes: 1) constructing the network architecture where the identities of nodes are legal, including: neighboring node discovery; performing identities certification and shared key negotiation between a node and the neighbor node; 2) constructing a secure switching device architecture, including: establishing a shared key between every two of the switch devices.


