Secure Overlay Network Identity-Based Access Decentralized Topology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Internet infrastructure is not designed to meet modern enterprise requirements, leading to inadequate cybersecurity and networking solutions that address symptoms rather than core design flaws, particularly in decentralized environments where the network perimeter has disappeared.

Innovation Solution

A secure overlay network is created on top of the public Internet, featuring identity-based access, fully encrypted private segments, improved protocols, and a decentralized topology, allowing any two nodes to communicate as if they are on the same local area network, with a controller managing user authentication, policy enforcement, and optimized routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure overlay network is created on top of the public Internet, then security and connectivity are enhanced, but device complexity and implementation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements an overlay network that nests within the existing public Internet infrastructure. The overlay network creates virtual tunnels and encrypted channels on top of the underlying Internet protocol stack, allowing secure communication without replacing the existing network infrastructure. This nesting approach provides enhanced security while leveraging the established Internet backbone.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces overlay network nodes and gateway devices as intermediary elements between end devices and the public Internet. These intermediaries handle encryption, decryption, and routing operations, isolating the complexity from end users while providing secure communication. The gateway devices act as mediators that translate between overlay and underlay network protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity-based access and encryption are implemented, then security is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary authentication and key exchange operations during the connection establishment phase. Identity verification and encryption key generation are performed before data transmission begins, allowing subsequent communication to use pre-established secure channels. This reduces the energy cost of repeated authentication handshakes during active communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different security measures to different parts of the network based on their specific requirements. High-value data streams receive stronger encryption and more frequent key rotation, while less sensitive traffic uses lighter security protocols. This localized approach to security optimizes the balance between protection and energy consumption.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If decentralized topology is implemented, then network resilience and adaptability are improved, but routing complexity and management difficulty increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidrouting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where overlay network nodes continuously exchange routing information and network status data. Route optimization algorithms use this feedback to dynamically adjust path selection based on current network conditions, node availability, and security requirements. This allows the decentralized network to self-optimize without centralized control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent designs overlay network nodes with multi-functional capabilities that handle authentication, encryption, routing, and data forwarding. This universal node design simplifies the overall system by having each node perform multiple functions rather than requiring specialized devices for each operation, reducing management complexity despite the decentralized topology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11936629B2System and method for creating a secure hybrid overlay network
Publication Date: 2024.03.19 VMWARE INC
  • US11936629B2 patent drawing
  • US11936629B2 patent drawing
  • US11936629B2 patent drawing

AI summary

A system and method for creating a secure overlay network on top of the public Internet, optionally by creating an identity-based network in which user identities are the identifiers rather than IP addresses, and whereas only authenticated and authorized users whose identity has been established have visibility and access to the network; establishing fully encrypted and private network segments; providing superior performance through improved protocols and routing; and implementing a decentralized topology that allows any two nodes on it to communicate regardless of each node's location or network settings—as if the two nodes are on the same local area network.