Secure Network Architecture via Dedicated Security Gateway Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wired local area networks lack effective data security measures, leading to hidden security dangers and increased computing load on switch devices, with existing methods like hop-by-hop encryption causing transmission delays and inefficiencies.

Innovation Solution

A method for establishing a secure network architecture through identity authentication and shared key negotiation between nodes, constructing a three-stage secure communication process using shared keys between switch devices to ensure secure data transmission without the need for static key pairs or hop-by-hop encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hop-by-hop encryption is implemented to ensure data security, then network security is improved, but computing load on switch devices increases and transmission delay increases

Engineering Contradiction:
Improvenetwork securityVSAvoidtransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the encryption process by introducing dedicated security gateway nodes that handle encryption/decryption operations, separating this function from regular switch devices. This allows switch devices to forward packets without performing encryption operations, reducing their computing load and transmission delay while maintaining security through the gateway nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security gateway nodes as intermediary components between the data transmission path and the encryption/decryption operations. These gateways act as mediators that handle the computationally intensive security functions, allowing the main transmission path to operate efficiently without security-related delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If static key pairs are distributed to all nodes to establish session keys, then secure communication between nodes is achieved, but key distribution and updating processes become extremely complicated

Engineering Contradiction:
Improvecommunication securityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key distribution function from the general node-to-node communication and concentrates it in dedicated security gateway nodes. These gateways maintain and manage the key pairs, extracting the complexity of key management from the regular communication process and centralizing it in specialized components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a self-service key generation mechanism where security gateway nodes automatically generate and manage key pairs for themselves and other gateways. This eliminates the need for manual or complex external key distribution systems, as the gateways service their own key management needs autonomously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8843748B2Method for establishing secure network architecture, method and system for secure communication
Publication Date: 2014.09.23 CHINA IWNCOMM
  • US8843748B2 patent drawing
  • US8843748B2 patent drawing
  • US8843748B2 patent drawing

AI summary

A method for establishing a secure network architecture, a method and system for secure communication are provided. The method for establishing a secure network architecture includes: 1) constructing the network architecture where the identities of nodes are legal, including: neighboring node discovery; performing identities certification and shared key negotiation between a node and the neighbor node; 2) constructing a secure switching device architecture, including: establishing a shared key between every two of the switch devices.