Secure Communication Network Using Intermediary Control Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems for secure data transmission in e-commerce and transactions face challenges in maintaining anonymity and data privacy across different jurisdictions, while ensuring secure and traceable data exchange.

Innovation Solution

A communication network comprising a first control node and a second control node, forming private communication networks to enable secure and anonymous data transmission between them, with an intermediary node managing requests and responses to maintain user privacy and data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct communication between sender and recipient is implemented, then communication speed and simplicity are improved, but confidentiality and data privacy across jurisdictions are compromised

Engineering Contradiction:
Improvecommunication speedVSAvoiddata privacy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces control nodes as intermediaries between senders and recipients. These control nodes receive encrypted messages, manage key distribution, and facilitate communication without being able to decrypt the content. This intermediary structure enables fast communication while maintaining jurisdictional privacy boundaries, as each control node operates within its own legal framework without accessing actual message content.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication system is segmented into multiple independent components: sender units, recipient units, control nodes, and key management systems. Each segment operates independently with specific functions, allowing the system to maintain privacy in different jurisdictions while enabling efficient communication. The segmentation prevents any single point from having access to both communication speed and decryption capabilities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If sender and recipient identities are made known to the communication system, then traceability and non-repudiation are improved, but anonymity and user privacy are worsened

Engineering Contradiction:
ImprovetraceabilityVSAvoidanonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system uses cryptographic keys and digital signatures as copies of identity information rather than storing actual personal data. Control nodes verify identities through cryptographic proofs without retaining personal identifying information. This allows the system to establish traceability for legal purposes while maintaining user anonymity in practice, as the 'copy' of identity (cryptographic key) cannot be reverse-engineered to reveal personal information.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the parameter of identity representation from personal data to cryptographic identifiers. By transforming identity into mathematical keys and signatures, the system enables traceability through cryptographic verification while preventing any form of personal identification. This parameter change allows simultaneous achievement of both traceability and anonymity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If control nodes store and process communication data, then message integrity and security management are improved, but the risk of unauthorized access and data breaches increases

Engineering Contradiction:
Improvemessage integrityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption capability from the control nodes and places it exclusively with the communicating parties (senders and recipients) through private key management. Control nodes only handle encrypted data and metadata, never the actual message content in decrypted form. This extraction eliminates the primary vulnerability point where stored data could be accessed unauthorizedly, while control nodes still perform integrity verification through cryptographic protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates an inert cryptographic environment where control nodes handle only encrypted data that is mathematically inert - it cannot be read or manipulated without the proper private keys. This inert environment protects against unauthorized access because the data remains in an unusable encrypted state throughout its passage through control nodes, eliminating the risk of data breaches even if control node security is compromised.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

4Ease of operation

If a centralized communication system is implemented, then coordination and key management are simplified, but single points of failure and jurisdictional conflicts arise

Engineering Contradiction:
Improvekey managementVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The centralized key management function is segmented into distributed control nodes, each responsible for specific cryptographic operations within their jurisdiction. Rather than one central authority holding all keys, the system divides key management responsibilities across multiple independent nodes that cooperate through standardized protocols. This segmentation maintains operational simplicity for users while distributing the architectural complexity across manageable independent units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Control nodes are designed with universal functionality to handle multiple types of cryptographic operations (key generation, signature verification, encrypted data routing) through standardized interfaces. This multi-functionality allows different control nodes to work together seamlessly despite being physically distributed, maintaining the ease of operation of a centralized system while achieving the fault tolerance and jurisdictional independence of a distributed architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9419945B2Systems and methods for providing and operating a secure communication network
Publication Date: 2016.08.16 REGIFY
  • US9419945B2 patent drawing
  • US9419945B2 patent drawing
  • US9419945B2 patent drawing

AI summary

A communication network comprises a first control node (101) and at least one second control node (103), wherein the first control node and the second control node form a first-level communication network (113) which communicatively couples the first control node to the second control node, wherein the first control node comprises a first intermediary node communication module (123) for forming a first second-level communication network (121) between the first control node (101) and a first intermediary node (105), wherein the first intermediary node communication module is adapted to receive an anonymous request (143) from the first intermediary node (105), the anonymous request (143) being based on a first user request (141) transmitted from a first user node (109) to the first intermediary node (105), wherein the first control node (101) is adapted to transmit the anonymous request (143) to the second control node (103).