Secure Transaction Routing via Dynamic Path Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication technologies are vulnerable to eavesdropping and message injection attacks, as they rely on traditional routing protocols that do not adequately ensure the integrity and authenticity of transactions between network devices.

Innovation Solution

The implementation of intelligent routing protocols that intentionally inject alternative message routes across and within networks, using techniques such as rotating path sequences, 'port knocking,' and multi-path routing validation to enhance security by making it difficult for unauthorized parties to intercept or modify messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional routing protocols are used for secure communication, then ease of operation is maintained, but security against eavesdropping and message injection attacks deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic routing where the path for communication messages changes over time based on predetermined sequences. Routes are rotated between different available paths, making it difficult for attackers to predict or intercept communications. This dynamic approach transforms static routing into an adaptive security mechanism without requiring complex real-time decision-making.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes predetermined routing sequences and valid path definitions before communication occurs. These preliminary route configurations are stored and validated in advance, allowing the system to quickly switch between known secure paths without performing complex real-time analysis. The preliminary action of defining valid routes beforehand simplifies the operational complexity during actual communication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple transmission routes are used to ensure data integrity, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the network into multiple segmented paths between communicating devices. Each path is defined as a separate valid route with specific intermediate nodes. This segmentation allows the system to distribute traffic across multiple simpler paths rather than managing one complex dynamic route, reducing overall system complexity while maintaining security through path diversity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates multiple copies of communication messages and sends them through different predetermined paths simultaneously. Each path copy follows a simple, pre-defined route rather than requiring complex real-time routing decisions. This copying approach provides security through redundancy while keeping each individual path simple and manageable.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3447668B1Utilizing routing for secure transactions
Publication Date: 2020.05.13 ITRON INC
  • EP3447668B1 patent drawingFigure 1~2
  • EP3447668B1 patent drawingFigure 3

AI summary

The present disclosure relates to methodologies, networks, and nodes for providing secure transaction routing among network components. Network transactions (messages) may be intentionally routed though networks using different paths where the act of following the particular node paths or traversing particular nodes provides a security enhancing feature for the messages. A transaction receiving node will examine the paths taken from a sending node to determine if the paths correspond to predetermined paths to verify the authenticity of the transaction. In some embodiments, predetermined paths may change in a predetermined sequence where the sequence itself becomes a portion of the security feature.