Selective Content Routing Protocol for ICN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet Protocol (IP) networks lack the ability to support content-based virtual private networks (VPNs) that allow for secure and controlled content routing and caching, as they rely on topological links and do not account for privacy and security policies in content forwarding and storage.

Innovation Solution

A selective content routing and storage protocol is implemented in Information-Centric Networks (ICNs) using secured router identifiers (SRIDs) and virtual private group (VPN) identifiers to control content routing and caching, allowing for the creation of content-based VPNs that isolate ICN resources and adhere to service level agreements (SLAs) for performance, security, and availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional IP networks are used for content routing, then network infrastructure is simple and widely compatible, but content-based VPNs with secure and controlled routing cannot be supported

Engineering Contradiction:
Improvecontent-based VPN supportVSAvoidrouting protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the content routing process by introducing separate components: content name prefixes for identification, SRID lists for authorization, and VPN ID lists for isolation. This segmentation allows traditional IP infrastructure to be enhanced with content-aware routing capabilities without complete system replacement

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent embeds content routing information (content names, SRID lists, VPN ID lists) within existing IP packet structures. The content routing headers are nested within IP packets, allowing content-based routing to operate alongside traditional IP routing without requiring separate physical infrastructure

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If content is flooded to all neighboring nodes for maximum dissemination, then content availability is improved, but security and privacy policies cannot be enforced

Engineering Contradiction:
Improvecontent availabilityVSAvoidsecurity and privacy violations
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making routing and caching permissions location-specific through SRID lists. Each content router checks whether its SRID is included in the authorized list before processing content, allowing selective dissemination to specific locations while maintaining security policies

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces content name prefixes and authorization lists as intermediaries between content sources and recipients. These intermediaries carry routing and security information that enables controlled dissemination without requiring direct trust relationships between all network participants

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If all content routers cache all received content for maximum content delivery capability, then content delivery performance is improved, but network storage resources are wasted

Engineering Contradiction:
Improvecontent delivery performanceVSAvoidstorage resource waste
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent applies local quality by making caching permissions location-specific through SRID lists. Each content router determines whether to cache content based on whether its SRID is included in the authorized list, allowing selective caching that optimizes storage resource usage while maintaining content delivery performance where needed

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9379970B2Selective content routing and storage protocol for information-centric network
Publication Date: 2016.06.28 FUTUREWEI TECHNOLOGIES INC
  • US9379970B2 patent drawing
  • US9379970B2 patent drawing
  • US9379970B2 patent drawing

AI summary

A network component comprising a receiver configured to receive an advertisement for a content name for content associated with a list of secured router identifiers (SRIDs) that indicates a plurality of content routers authorized for routing and caching the content, a processor configured to determine whether to flood the advertisement to a plurality of neighboring nodes if a locally assigned SRID is included in the list of SRIDs received in the advertisement or to drop the advertisement otherwise, a transmitter configured to flood the advertisement on a plurality of ports coupled to the neighboring nodes, and a storage configured to cache received content if the received content is associated with the locally assigned SRID.