Secure Packet Transmission via Required Node Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current non-removable embedded smart cards and trusted environments face security risks, communication complexities, and accountability uncertainties when receiving sensitive data remotely.
Innovation Solution
Implementing a policy for secure packet transmission using required node paths and cryptographic signatures to ensure that sensitive data is transmitted through a predetermined secure path, verified by cryptographic signatures from each node, and enforced end-to-end, allowing only trusted nodes to handle the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive data is transmitted remotely to embedded smart cards and trusted environments, then data accessibility is improved, but security risks increase
Solution Approach 1:
The patent applies preliminary action by pre-defining required node paths and cryptographic signature requirements before data transmission occurs. The source node determines and specifies the exact path through trusted intermediate nodes beforehand, and each node along the path pre-prepares cryptographic signatures to verify data integrity and authenticity during transmission.
Solution Approach 2:
The patent uses intermediary trusted nodes as mediators between the source node and the target embedded smart card or trusted environment. These intermediate nodes act as verified relays that forward data while maintaining security, with each node cryptographically signing the data to ensure it hasn't been tampered with, thus mediating the transmission securely.
2Reliability
If cryptographic signatures are verified at each node along the transmission path, then security is improved, but communication complexity increases
Solution Approach 1:
The patent segments the cryptographic verification process into discrete steps at each intermediate node along the transmission path. Instead of one complex end-to-end verification, each node independently verifies cryptographic signatures for its specific segment of the path, making the overall complex process manageable through division into smaller, standardized verification tasks.
Solution Approach 2:
Each intermediate node autonomously performs cryptographic verification of the data received from the previous node and prepares its own cryptographic signature for forwarding to the next node. This self-service approach at each node eliminates the need for centralized control of the verification process, reducing overall communication complexity while maintaining security.
3Reliability
If a predetermined required node path is enforced for data transmission, then accountability is improved, but routing flexibility decreases
Solution Approach 1:
The source node performs preliminary action by determining and specifying the exact required node path before transmission begins. This pre-determined path establishes clear accountability for which trusted nodes should handle the data, while the source node retains the flexibility to choose the most appropriate path based on current security conditions and node availability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques (400, 600, 700) and apparatuses (102, 106, 108, 800) are described that enable a policy for secure packet transmission using required node paths and cryptographic signatures. Policy data including a required node path (110) is appended to a packet (112). The packet (112) containing sensitive data is transmitted through intermediate nodes (108). Each of the intermediate nodes (108) may cryptographically sign the packet. A final device (108-4, 106) receives the packet (112) and determines, based on cryptographic signatures of intermediate nodes (108), that an actual node path of the packet through the infrastructure matches required node path (110). These techniques and apparatuses enable a secure execution environment (SEE) of a target device to receive trustworthy sensitive data.