Trust-Based Routing for Malicious Router Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data network routing protocols are vulnerable to security issues such as malicious routers sending erroneous information, leading to chaos, packet loss, and exposure of confidential data, with existing security measures being ineffective against compromised legitimate routers and incurring significant overhead.

Innovation Solution

Assigning trust values to routers based on reliability, using a Dynamic Distributed Trust Model that considers both inherent and observed trust factors to calculate route metrics, thereby selecting more reliable paths for data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are implemented to protect against malicious routers, then security is improved, but system overhead increases significantly

Engineering Contradiction:
Improverouting securityVSAvoidsecurity overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-calculating trust metrics for multiple potential routing paths before data transmission occurs. Routers exchange trust information and compute route metrics in advance, so when a routing decision is needed, the safest path is already identified without requiring complex real-time security analysis. This resolves the contradiction by preparing security measures beforehand, reducing overhead during actual operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service through distributed trust metric calculation where each router independently calculates its own trust metrics for neighboring routers based on locally observed data and exchanged information. Rather than relying on a centralized security authority that would create overhead, each router serves its own security needs by autonomously evaluating path safety based on trust metrics, eliminating the need for complex centralized security management infrastructure.

Inventive Principle:
Principle #25Self-service

2Reliability

If trust-based route selection is implemented, then packet loss is reduced, but routing complexity increases

Engineering Contradiction:
Improvepacket delivery reliabilityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the traditional routing metric (hop count, bandwidth) into a trust-based metric that incorporates security reliability. Each router calculates a composite trust metric that combines multiple factors including historical performance, observed behavior, and exchanged trust information. This parameter transformation allows routers to select paths with higher packet delivery reliability without requiring fundamentally new routing algorithms, as the existing shortest-path algorithms can be applied using the new trust metric.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If distributed trust model is used instead of centralized management, then system scalability is improved, but trust calculation complexity increases

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidtrust calculation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the trust calculation process into localized segments at each router rather than requiring global centralized computation. Each router independently calculates trust metrics for its immediate neighbors based on local observations and exchanged information, without needing to process data from the entire network. This segmentation enables the system to scale to large networks while keeping individual router calculations manageable, as each router only needs to evaluate its local neighborhood rather than the whole network.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7920558B2Method of operating a network
Publication Date: 2011.04.05 BRITISH TELECOM PLC
  • US7920558B2 patent drawing
  • US7920558B2 patent drawing
  • US7920558B2 patent drawing

AI summary

A data network has a number of inter-connected router devices forward received packets of data towards a destination node in accordance with a routing table associated with each router. A trust value is assigned to one or more other router devices, or links between router devices, in the network. A route metric is calculated in respect of one or more paths for forwarding on received data packets for onward transmission towards a specified destination. A next hop destination is selected for onward transmission of each such received packet to be forwarded on the basis of the calculated route metric for each applicable path. Each route metric is calculated in dependence upon the trust value assigned to one or more of the router or routers within each such path.