Secure Routing via Trust Anchors and Geolocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-security measures are inadequate in tracing the origin of cyber attacks, leading to difficulties in retaliating against rogue users and preventing denial of service (DoS) and network data interception attacks, as they often lack clear traceability and authority to respond effectively.

Innovation Solution

A method and system for secure routing based on a degree of trust, where network nodes are assigned levels of trust based on their physical location verification using satellite geolocation techniques or network ping ranging measurements, allowing for encrypted tunneling and secure data transmission through trusted paths, with boundary firewall routers and autonomous systems to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cyber-security measures are used, then network connectivity is maintained, but traceability of attack origin is lost and security response capability deteriorates

Engineering Contradiction:
Improvetraceability of attack originVSAvoidrouting security infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces trust anchors and certificate authorities as intermediary entities that issue digital certificates to network nodes. These intermediaries enable traceability of attack origins by providing a chain of trust that links back to known secure entities, allowing recipients to verify the identity and location of message senders without requiring direct knowledge of the entire network topology.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a spatial dimension to traditional routing by incorporating geographic location information into the trust verification process. By using GPS coordinates and geographic boundary definitions, the system creates a new dimension for security validation that goes beyond traditional network-layer authentication, enabling location-based trust assessment.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If geographic trust verification is implemented, then security against rogue users is improved, but network operation complexity increases

Engineering Contradiction:
Improvesecurity against rogue usersVSAvoidnetwork operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary geographic verification by defining trusted geographic boundaries and obtaining location certificates before actual message transmission. Network nodes pre-validate their locations against trusted boundary definitions and store their location certificates, so that when messages are received, the verification process is already prepared and can proceed efficiently without real-time complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables network nodes to self-verify their geographic locations using onboard GPS receivers and automatically generate location certificates. Each node independently performs its own geographic trust verification by comparing its recorded coordinates against the trusted boundary definitions, eliminating the need for centralized real-time verification and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Loss of information

If location-based trust assignment is used, then identification of attack origin is improved, but data transmission overhead increases

Engineering Contradiction:
Improveidentification of attack originVSAvoiddata transmission overhead
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential location information (GPS coordinates and trusted boundary identifier) from the complete geographic data set and embeds it in the location certificate. By taking out only the critical traceability elements rather than transmitting full geographic datasets, the system achieves effective attack origin identification while minimizing data transmission overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If encrypted tunneling through trusted paths is implemented, then data security is improved, but routing complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidrouting infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a separate encrypted communication dimension that operates independently from the standard routing infrastructure. By establishing secure tunnels through the trusted network path and using cryptographic protocols, the system provides enhanced data security without fundamentally altering the underlying routing complexity, as the encrypted channels can be implemented as layered protocols over existing routes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2810419B1Secure routing based on degree of trust
Publication Date: 2021.09.22 THE BOEING CO
  • EP2810419B1 patent drawingFigure 1
  • EP2810419B1 patent drawingFigure 2
  • EP2810419B1 patent drawingFigure 3~4

AI summary

A system, method, and apparatus for secure routing based on a degree of trust are disclosed herein. The disclosed method involves assigning a level of trust to at least one network node, and utilizing the level of trust to determine a degree of security of the network node(s). The level of trust of the network node(s) is related to an amount of certainty of the physical location of the network node(s). The amount of certainty is attained from the network node(s) being located in a known secure location, and/or from verification of the physical location of the network node(s) by using satellite geolocation techniques or by using network ping ranging measurements. The method further involves utilizing the level of trust of the network node(s) to determine a degree of trust of at least one path for routing the data, where the path(s) includes at least one of the network nodes.