Transparent Bridge for Crypto-Partitioned WAN Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wide-area networks (WANs) are susceptible to equipment failures and cyber-attacks, leading to impaired connectivity for mission applications, with existing approaches being inefficient for UDP-based applications and multicast data flows.

Innovation Solution

A computing device positioned in a plain-text enclave behind an inline network encryptor monitors the status of a cipher-text WAN by analyzing data packets, using a signaling mechanism to share network state information and implement congestion prevention strategies and transport layer-independent overlay routing to correct errors and restore connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a fully distributed network optimization technique based on cooperative game theory is used to allocate network resources, then network resource allocation efficiency is improved, but performance for UDP-based applications and multicast data flows deteriorates

Engineering Contradiction:
Improvenetwork resource allocation efficiencyVSAvoidperformance for UDP-based applications and multicast data flows
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the network into multiple enclaves with dedicated monitoring devices, allowing independent optimization for different traffic types (UDP, multicast, TCP) rather than applying a single distributed optimization approach to all traffic, thus resolving the contradiction between overall resource allocation efficiency and specific application performance

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary monitoring devices positioned in each enclave that actively monitor network status and coordinate with other enclaves. These intermediaries enable efficient resource allocation while providing specialized support for UDP and multicast traffic, maintaining both overall efficiency and specific application performance

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If monitoring and correction operations are performed within enclaves using plain-text-side and overlay routing, then connectivity protection is improved, but network overhead increases

Engineering Contradiction:
Improveconnectivity protectionVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by proactively monitoring network status indicators in data packets before connectivity issues occur. The monitoring devices detect potential problems early and can preemptively route around issues, providing connectivity protection without requiring extensive reactive corrections that would increase network overhead

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback mechanisms where monitoring devices continuously analyze network status and adjust routing decisions in real-time. This feedback loop enables efficient connectivity protection by making targeted routing adjustments only when and where needed, rather than applying blanket overhead across all network traffic

Inventive Principle:
Principle #23Feedback

3Productivity

If existing distributed network optimization approaches are used, then cumulative network performance is maximized, but recovery time from network events increases

Engineering Contradiction:
Improvecumulative network performanceVSAvoidrecovery time from network events
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent prepares for network events in advance by continuously monitoring network status indicators and maintaining ready-to-execute routing alternatives. When network events occur, the system can immediately switch to pre-planned recovery paths, significantly reducing recovery time while maintaining cumulative network performance through coordinated enclave responses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic response mechanisms where monitoring devices can rapidly adjust routing decisions based on real-time network conditions. This dynamic capability allows the system to maintain optimal cumulative performance during normal operation and quickly adapt to network events, reducing recovery time through flexible, real-time reconfiguration rather than static optimization

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11729185B2Transparent bridge for monitoring crypto-partitioned wide-area network
Publication Date: 2023.08.15 ARCHITECTURE TECH CORP
  • US11729185B2 patent drawing
  • US11729185B2 patent drawing
  • US11729185B2 patent drawing

AI summary

This disclosure is directed to monitoring a crypto-partitioned, or cipher-text, wide-area network (WAN). A first computing device may be situated in a plain-text portion of a first enclave behind a first inline network encryptor (INE). A second device may be positioned in a plain-text portion of a second enclave behind a second INE. The two enclaves may be separated by a cipher-text WAN, over which the two enclaved may communicate. The first computing device may receive a data packet from the second computing device. The first computing device may then determine contents of a header of the data packet. The first computing device may, based at least in part on the contents of the header of the data packet, determine a status of the cipher-text WAN.