Secure Routing via Physical Node Location Constraints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current position-based routing technologies prioritize efficiency over security, making networks vulnerable to cyber attacks like man-in-the-middle attacks, especially in routing data through unauthenticated network nodes.
Innovation Solution
Implementing a method for secure routing that uses the physical locations of network nodes to enforce security constraints, such as routing data through nodes authenticated by satellite geolocation or network ping ranging measurements, and employing encrypted tunneling for unverifiable nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If position-based routing is used to optimize network route efficiency, then routing speed and resource utilization are improved, but network security deteriorates due to vulnerability to cyber attacks like man-in-the-middle attacks
Solution Approach 1:
The system performs preliminary authentication of network nodes using satellite geolocation and network ranging measurements before routing data through them. This advance verification ensures that only authenticated nodes are included in the routing path, preventing man-in-the-middle attacks while maintaining efficient position-based routing for authenticated nodes
Solution Approach 2:
The patent introduces encrypted tunneling as an intermediary mechanism for data transmission through unverifiable network nodes. The encryption layer acts as a mediator that protects data integrity and confidentiality even when passing through potentially compromised nodes, allowing efficient routing while mitigating security risks
2Reliability
If satellite geolocation authentication is implemented for all network nodes, then network security is improved, but system complexity and authentication time increase
Solution Approach 1:
The system applies different authentication methods based on the specific characteristics and location requirements of each network node. Satellite geolocation is used for nodes requiring high security, while network ping ranging is used for nodes where satellite authentication is unavailable or unnecessary, creating a tailored authentication approach that balances security with system complexity
Solution Approach 2:
The patent implements selective authentication where not all network nodes require satellite geolocation authentication. Instead, authentication is applied partially to nodes based on security requirements and availability, reducing overall system complexity while maintaining security for critical nodes
3Reliability
If encrypted tunneling is used for unverifiable nodes, then data security is improved, but transmission overhead and processing time increase
Solution Approach 1:
Encrypted tunneling is applied selectively only to packets routing through unverifiable nodes, while packets through authenticated nodes use standard routing without additional encryption overhead. This partial application minimizes transmission delay for the majority of traffic while maintaining security for sensitive communications
Data Source
AI summary
A system, method, and apparatus for secure routing based on the physical location of routers are disclosed herein. The disclosed method for secure data transmission of at least one data packet through a plurality of network nodes involves defining a source network node, a destination network node, and at least one security constraint, which is based on the physical location of at least one of the network nodes. The method further involves comparing available network nodes with the security constraint(s) to determine which of the available network nodes meet the security constraint(s) and, thus, are qualified network nodes. Additionally, the method involves determining a route comprising at least one of the qualified network nodes to route the data packet(s) through from the source network node to the destination network node. Further, the method involves transmitting the data packet(s) through the route of the qualified network node(s).


