Secure Packet Transmission via Required Node Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current non-removable embedded smart cards and trusted environments face security risks, communication complexities, and accountability uncertainties when receiving sensitive data remotely.

Innovation Solution

Implementing a policy for secure packet transmission using required node paths and cryptographic signatures to ensure that sensitive data is transmitted through a predetermined secure path, verified by cryptographic signatures from each node, and enforced end-to-end, allowing only trusted nodes to handle the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is transmitted remotely to embedded smart cards and trusted environments, then data accessibility is improved, but security risks increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-defining required node paths and cryptographic signature requirements before data transmission occurs. The source node determines and specifies the exact path through trusted intermediate nodes beforehand, and each node along the path pre-prepares cryptographic signatures to verify data integrity and authenticity during transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses intermediary trusted nodes as mediators between the source node and the target embedded smart card or trusted environment. These intermediate nodes act as verified relays that forward data while maintaining security, with each node cryptographically signing the data to ensure it hasn't been tampered with, thus mediating the transmission securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic signatures are verified at each node along the transmission path, then security is improved, but communication complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic verification process into discrete steps at each intermediate node along the transmission path. Instead of one complex end-to-end verification, each node independently verifies cryptographic signatures for its specific segment of the path, making the overall complex process manageable through division into smaller, standardized verification tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each intermediate node autonomously performs cryptographic verification of the data received from the previous node and prepares its own cryptographic signature for forwarding to the next node. This self-service approach at each node eliminates the need for centralized control of the verification process, reducing overall communication complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If a predetermined required node path is enforced for data transmission, then accountability is improved, but routing flexibility decreases

Engineering Contradiction:
ImproveaccountabilityVSAvoidrouting flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The source node performs preliminary action by determining and specifying the exact required node path before transmission begins. This pre-determined path establishes clear accountability for which trusted nodes should handle the data, while the source node retains the flexibility to choose the most appropriate path based on current security conditions and node availability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2823619B1Policy for secure packet transmission using required node paths and cryptographic signatures
Publication Date: 2019.12.25 GOOGLE TECHNOLOGY HOLDINGS LLC
  • EP2823619B1 patent drawingFigure 1
  • EP2823619B1 patent drawingFigure 2
  • EP2823619B1 patent drawingFigure 3

AI summary

Techniques (400, 600, 700) and apparatuses (102, 106, 108, 800) are described that enable a policy for secure packet transmission using required node paths and cryptographic signatures. Policy data including a required node path (110) is appended to a packet (112). The packet (112) containing sensitive data is transmitted through intermediate nodes (108). Each of the intermediate nodes (108) may cryptographically sign the packet. A final device (108-4, 106) receives the packet (112) and determines, based on cryptographic signatures of intermediate nodes (108), that an actual node path of the packet through the infrastructure matches required node path (110). These techniques and apparatuses enable a secure execution environment (SEE) of a target device to receive trustworthy sensitive data.