Trusted Path Establishment in Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission systems in multi-node networks face challenges in ensuring the security of sensitive information, as no encryption method is completely secure, and it is difficult to prevent data from passing through nodes with less than desirable security levels, especially with the increasing demands of 5G data transmission.

Innovation Solution

A method and apparatus for establishing trusted communication paths in a network by receiving security confidence information from trusted elements, generating unique digital certificates, and transmitting information through trusted paths based on a trusted path policy, ensuring that sensitive data is transmitted over secure segments between trusted nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted through a multi-node network, then information can be delivered from source to destination, but security of the transmitted information deteriorates due to potential exposure at untrusted nodes

Engineering Contradiction:
Improveinformation securityVSAvoidnetwork path management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network path is segmented into trusted and untrusted portions. The system identifies and isolates trusted network elements (nodes, links, or domains) along the transmission path, creating discrete secure segments. This segmentation allows sensitive data to be routed only through verified trusted segments while permitting non-sensitive data to use broader network paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted path management system acts as an intermediary between the data source and destination. This intermediary evaluates security confidence information, generates trusted path digital certificates, and provides trusted path information to guide data transmission. The intermediary resolves the complexity of path selection by centralizing the trust evaluation and path determination functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to sensitive data before transmission, then confidentiality is improved, but security is still insufficient because untrusted nodes may still compromise the data

Engineering Contradiction:
Improvedata confidentialityVSAvoidsecurity assurance
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by pre-identifying and certifying trusted network elements before data transmission occurs. Security confidence information is collected and evaluated in advance, and trusted path digital certificates are generated beforehand. This preliminary establishment of trust relationships ensures that when data needs to be transmitted, pre-verified secure paths are already available.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides beforehand cushioning by creating multiple trusted path options and storing trusted path information in advance. When transmission needs to occur, the system already has pre-evaluated secure paths available, cushioning against the risk of no secure path being available at the moment of transmission. This also cushions against potential path failures by having alternative trusted paths ready.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If operators mandate security-sensitive information transmission over trusted segments, then network security is improved, but device complexity increases due to path establishment and management requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidtrusted path management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted path management system is designed with multi-functionality to handle various tasks: collecting security confidence information from multiple sources, evaluating different types of security parameters, generating digital certificates, storing trusted path information, and providing path recommendations. This universal design consolidates multiple security management functions into a single system, reducing overall complexity rather than increasing it.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Network elements can self-register with the trusted path management system by providing their security confidence information. The system automatically evaluates this information and generates appropriate trusted path digital certificates without requiring manual intervention for each element. This self-service capability reduces operational complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11949718B2Establishing a trusted path and transmitting information via a network of untrusted elements
Publication Date: 2024.04.02 ARRIS ENTERPRISES LLC
  • US11949718B2 patent drawing
  • US11949718B2 patent drawing
  • US11949718B2 patent drawing

AI summary

An overlay to existing infrastructure that establishes trusted paths in a communication network to fulfill a fundamental need to identify and protect a trusted plane of devices and/or applications on a need specific basis is described. Establishing trusted paths operationally fulfills a fundamental need to identify and protect a trusted plane of devices and/or applications on a need specific basis as an overlay to the existing relatively unsecured network.